I want to thank the forum very much for recently helping me. By following previously posted instructions I was able to remove most of the virtumond.dll virus from my computer. To do this I ran multiple passed of the following programs:
CCleaner
Spybot - Search and Destroy
SUPERAntiSpyware
Vundo Fix
VirtumundoBegone
It appears that I got rid of most of the virus but something still remains because I now get the following error message at startup:
RunDLL
Error loading C:\WINDOWS\system32\dgeknntu.dll
The specified module could not be found.
Here is the sequence of steps I have taken to try to fix this:
1. Using CCleaner, I found the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Name: BM3fad8bb3
Type: REG_SZ
Data: Rundll32.exe "C:\WINDOWS\system32\dgeknntu.dll",s
I tried to delete the key manually through CCleaner. However, when I checked the registry the key was still there.
2. Using regedit, I again tried to delete the registry key. But, when I ran regedit a second time, the key was still there.
3. I rebooted in Safe Mode and deleted the registry key using regedit. When I ran regedit a second time the key was deleted.
4. I rebooted in Safe Mode and ran regedit to verify that the key was still gone. It was still deleted!
5. I rebooted in Normal Mode and the error message did not appear.
6. I rebooted in Normal Mode and the error message did appear.
7. I checked the registry and the "BM3fad8bb3" key had been added back.
So, it appears that a startup program that loads after the registry startup programs is reloading the "BM3fad8bb3" registry key.
How do I find the program that is doing this?
Using msconfig, I've generated boot logs and reviewed them but that didn't provide me with enough information to identify the program.
Also, I've use the Autoruns tool to look at the files that load at startup but I can't identify the program that way either.
My computer is running Windows XP SP2 and is updated with the latest security patches.
Can you please provide some suggestions as to how to proceed?
CCleaner
Spybot - Search and Destroy
SUPERAntiSpyware
Vundo Fix
VirtumundoBegone
It appears that I got rid of most of the virus but something still remains because I now get the following error message at startup:
RunDLL
Error loading C:\WINDOWS\system32\dgeknntu.dll
The specified module could not be found.
Here is the sequence of steps I have taken to try to fix this:
1. Using CCleaner, I found the following registry key:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Name: BM3fad8bb3
Type: REG_SZ
Data: Rundll32.exe "C:\WINDOWS\system32\dgeknntu.dll",s
I tried to delete the key manually through CCleaner. However, when I checked the registry the key was still there.
2. Using regedit, I again tried to delete the registry key. But, when I ran regedit a second time, the key was still there.
3. I rebooted in Safe Mode and deleted the registry key using regedit. When I ran regedit a second time the key was deleted.
4. I rebooted in Safe Mode and ran regedit to verify that the key was still gone. It was still deleted!
5. I rebooted in Normal Mode and the error message did not appear.
6. I rebooted in Normal Mode and the error message did appear.
7. I checked the registry and the "BM3fad8bb3" key had been added back.
So, it appears that a startup program that loads after the registry startup programs is reloading the "BM3fad8bb3" registry key.
How do I find the program that is doing this?
Using msconfig, I've generated boot logs and reviewed them but that didn't provide me with enough information to identify the program.
Also, I've use the Autoruns tool to look at the files that load at startup but I can't identify the program that way either.
My computer is running Windows XP SP2 and is updated with the latest security patches.
Can you please provide some suggestions as to how to proceed?
This post has been edited by jimr0707: 12 October 2008 - 09:24 PM

Help
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.

Back to top











