re
and here's the log from vbg. thanks alot
[11/05/2006, 20:40:15] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[11/05/2006, 20:40:24] - Detected System Information:
[11/05/2006, 20:40:24] - Windows Version: 5.1.2600, Service Pack 2
[11/05/2006, 20:40:24] - Current Username: Ant (Admin)
[11/05/2006, 20:40:24] - Windows is in NORMAL mode.
[11/05/2006, 20:40:24] - Searching for Browser Helper Objects:
[11/05/2006, 20:40:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:40:24] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - Checking for HKLM\...\Winlogon\Notify\vtstr
[11/05/2006, 20:40:24] - Found: HKLM\...\Winlogon\Notify\vtstr - This is probably Virtumundo.
[11/05/2006, 20:40:24] - Assigning {202B0345-79EA-4A71-988A-0C87B1FEC268} MSEvents Object
[11/05/2006, 20:40:24] - BHO list has been changed! Starting over...
[11/05/2006, 20:40:24] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:40:24] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} (MSEvents Object)
[11/05/2006, 20:40:24] - ALERT: Found MSEvents Object!
[11/05/2006, 20:40:24] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:40:24] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:40:24] - BHO 4: {61977312-9CD2-B371-D388-C4693FDD8EC8} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - Checking for HKLM\...\Winlogon\Notify\adglbc
[11/05/2006, 20:40:24] - Key not found: HKLM\...\Winlogon\Notify\adglbc, continuing.
[11/05/2006, 20:40:24] - BHO 5: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - No filename found. Continuing.
[11/05/2006, 20:40:24] - BHO 6: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:40:24] - BHO 7: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - No filename found. Continuing.
[11/05/2006, 20:40:24] - BHO 8: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:40:24] - BHO 9: {F18F04B0-9CF1-4b93-B004-77A288BEE28B} ()
[11/05/2006, 20:40:24] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:40:24] - Checking for HKLM\...\Winlogon\Notify\xlovduhs
[11/05/2006, 20:40:24] - Key not found: HKLM\...\Winlogon\Notify\xlovduhs, continuing.
[11/05/2006, 20:40:24] - Finished Searching Browser Helper Objects
[11/05/2006, 20:40:24] - *** Detected MSEvents Object
[11/05/2006, 20:40:24] - Trying to remove MSEvents Object...
[11/05/2006, 20:40:25] - Terminating Process: IEXPLORE.EXE
[11/05/2006, 20:40:25] - Terminating Process: RUNDLL32.EXE
[11/05/2006, 20:40:26] - Disabling Automatic Shell Restart
[11/05/2006, 20:40:26] - Terminating Process: EXPLORER.EXE
[11/05/2006, 20:40:26] - Suspending the NT Session Manager System Service
[11/05/2006, 20:40:27] - Terminating Windows NT Logon/Logoff Manager
[11/05/2006, 20:46:53] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[11/05/2006, 20:46:55] - Detected System Information:
[11/05/2006, 20:46:55] - Windows Version: 5.1.2600, Service Pack 2
[11/05/2006, 20:46:55] - Current Username: Ant (Admin)
[11/05/2006, 20:46:55] - Windows is in NORMAL mode.
[11/05/2006, 20:46:55] - Searching for Browser Helper Objects:
[11/05/2006, 20:46:55] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:46:55] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - No filename found. Continuing.
[11/05/2006, 20:46:55] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:46:55] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:46:55] - BHO 4: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - No filename found. Continuing.
[11/05/2006, 20:46:55] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:46:55] - BHO 6: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - No filename found. Continuing.
[11/05/2006, 20:46:55] - BHO 7: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:46:55] - BHO 8: {DD857116-8BFD-498C-9F40-FB91E52966EB} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - Checking for HKLM\...\Winlogon\Notify\vtstr
[11/05/2006, 20:46:55] - Found: HKLM\...\Winlogon\Notify\vtstr - This is probably Virtumundo.
[11/05/2006, 20:46:55] - Assigning {DD857116-8BFD-498C-9F40-FB91E52966EB} MSEvents Object
[11/05/2006, 20:46:55] - BHO list has been changed! Starting over...
[11/05/2006, 20:46:55] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:46:55] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - No filename found. Continuing.
[11/05/2006, 20:46:55] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:46:55] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:46:55] - BHO 4: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:46:55] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:55] - No filename found. Continuing.
[11/05/2006, 20:46:55] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:46:56] - BHO 6: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - No filename found. Continuing.
[11/05/2006, 20:46:56] - BHO 7: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:46:56] - BHO 8: {DD857116-8BFD-498C-9F40-FB91E52966EB} (MSEvents Object)
[11/05/2006, 20:46:56] - ALERT: Found MSEvents Object!
[11/05/2006, 20:46:56] - BHO 9: {F18F04B0-9CF1-4b93-B004-77A288BEE28B} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - Checking for HKLM\...\Winlogon\Notify\xlovduhs
[11/05/2006, 20:46:56] - Key not found: HKLM\...\Winlogon\Notify\xlovduhs, continuing.
[11/05/2006, 20:46:56] - BHO 10: {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - Checking for HKLM\...\Winlogon\Notify\wvutusp
[11/05/2006, 20:46:56] - Found: HKLM\...\Winlogon\Notify\wvutusp - This is probably Virtumundo.
[11/05/2006, 20:46:56] - Assigning {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2} MSEvents Object
[11/05/2006, 20:46:56] - BHO list has been changed! Starting over...
[11/05/2006, 20:46:56] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:46:56] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - No filename found. Continuing.
[11/05/2006, 20:46:56] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:46:56] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:46:56] - BHO 4: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - No filename found. Continuing.
[11/05/2006, 20:46:56] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:46:56] - BHO 6: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - No filename found. Continuing.
[11/05/2006, 20:46:56] - BHO 7: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:46:56] - BHO 8: {DD857116-8BFD-498C-9F40-FB91E52966EB} (MSEvents Object)
[11/05/2006, 20:46:56] - ALERT: Found MSEvents Object!
[11/05/2006, 20:46:56] - BHO 9: {F18F04B0-9CF1-4b93-B004-77A288BEE28B} ()
[11/05/2006, 20:46:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:46:56] - Checking for HKLM\...\Winlogon\Notify\xlovduhs
[11/05/2006, 20:46:56] - Key not found: HKLM\...\Winlogon\Notify\xlovduhs, continuing.
[11/05/2006, 20:46:56] - BHO 10: {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2} (MSEvents Object)
[11/05/2006, 20:46:56] - ALERT: Found MSEvents Object!
[11/05/2006, 20:46:56] - Finished Searching Browser Helper Objects
[11/05/2006, 20:46:56] - *** Detected MSEvents Object
[11/05/2006, 20:46:56] - Trying to remove MSEvents Object...
[11/05/2006, 20:46:57] - Terminating Process: IEXPLORE.EXE
[11/05/2006, 20:46:58] - Terminating Process: RUNDLL32.EXE
[11/05/2006, 20:46:58] - Disabling Automatic Shell Restart
[11/05/2006, 20:46:58] - Terminating Process: EXPLORER.EXE
[11/05/2006, 20:46:58] - Suspending the NT Session Manager System Service
[11/05/2006, 20:46:58] - Terminating Windows NT Logon/Logoff Manager
[11/05/2006, 20:52:27] - Re-enabling Automatic Shell Restart
[11/05/2006, 20:52:27] - File to disable: C:\WINDOWS\system32\vtstr.dll
[11/05/2006, 20:52:27] - Renaming C:\WINDOWS\system32\vtstr.dll -> C:\WINDOWS\system32\vtstr.dll.vir
[11/05/2006, 20:52:27] - File successfully renamed!
[11/05/2006, 20:52:27] - Removing HKLM\...\Browser Helper Objects\{DD857116-8BFD-498C-9F40-FB91E52966EB}
[11/05/2006, 20:52:27] - Removing HKCR\CLSID\{DD857116-8BFD-498C-9F40-FB91E52966EB}
[11/05/2006, 20:52:27] - Adding Kill Bit for ActiveX for GUID: {DD857116-8BFD-498C-9F40-FB91E52966EB}
[11/05/2006, 20:52:27] - Deleting ATLEvents/MSEvents Registry entries
[11/05/2006, 20:52:27] - Removing HKLM\...\Winlogon\Notify\vtstr
[11/05/2006, 20:52:27] - Searching for Browser Helper Objects:
[11/05/2006, 20:52:27] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:52:27] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:52:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:27] - No filename found. Continuing.
[11/05/2006, 20:52:27] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:52:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:27] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:52:27] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:52:27] - BHO 4: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:52:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:27] - No filename found. Continuing.
[11/05/2006, 20:52:27] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:52:27] - BHO 6: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:52:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:27] - No filename found. Continuing.
[11/05/2006, 20:52:27] - BHO 7: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:52:27] - BHO 8: {F18F04B0-9CF1-4b93-B004-77A288BEE28B} ()
[11/05/2006, 20:52:27] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:27] - Checking for HKLM\...\Winlogon\Notify\xlovduhs
[11/05/2006, 20:52:27] - Key not found: HKLM\...\Winlogon\Notify\xlovduhs, continuing.
[11/05/2006, 20:52:27] - BHO 9: {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2} (MSEvents Object)
[11/05/2006, 20:52:27] - ALERT: Found MSEvents Object!
[11/05/2006, 20:52:27] - Finished Searching Browser Helper Objects
[11/05/2006, 20:52:27] - *** Detected MSEvents Object
[11/05/2006, 20:52:27] - Trying to remove MSEvents Object...
[11/05/2006, 20:52:28] - Terminating Process: IEXPLORE.EXE
[11/05/2006, 20:52:29] - Terminating Process: RUNDLL32.EXE
[11/05/2006, 20:52:29] - Disabling Automatic Shell Restart
[11/05/2006, 20:52:29] - Terminating Process: EXPLORER.EXE
[11/05/2006, 20:52:29] - Suspending the NT Session Manager System Service
[11/05/2006, 20:52:29] - Terminating Windows NT Logon/Logoff Manager
[11/05/2006, 20:52:29] - Re-enabling Automatic Shell Restart
[11/05/2006, 20:52:29] - File to disable: C:\WINDOWS\system32\wvutusp.dll
[11/05/2006, 20:52:29] - Renaming C:\WINDOWS\system32\wvutusp.dll -> C:\WINDOWS\system32\wvutusp.dll.vir
[11/05/2006, 20:52:29] - File successfully renamed!
[11/05/2006, 20:52:29] - Removing HKLM\...\Browser Helper Objects\{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}
[11/05/2006, 20:52:29] - Removing HKCR\CLSID\{F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}
[11/05/2006, 20:52:29] - Adding Kill Bit for ActiveX for GUID: {F7999166-FDE6-49DA-9AFC-1F6A79E9D1F2}
[11/05/2006, 20:52:29] - Deleting ATLEvents/MSEvents Registry entries
[11/05/2006, 20:52:29] - Removing HKLM\...\Winlogon\Notify\wvutusp
[11/05/2006, 20:52:29] - Searching for Browser Helper Objects:
[11/05/2006, 20:52:29] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[11/05/2006, 20:52:29] - BHO 2: {202B0345-79EA-4A71-988A-0C87B1FEC268} ()
[11/05/2006, 20:52:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:29] - No filename found. Continuing.
[11/05/2006, 20:52:29] - BHO 3: {5EAA13F8-5513-D8DE-6B93-042F2DE1EE1E} ()
[11/05/2006, 20:52:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:29] - Checking for HKLM\...\Winlogon\Notify\aankmyf
[11/05/2006, 20:52:29] - Key not found: HKLM\...\Winlogon\Notify\aankmyf, continuing.
[11/05/2006, 20:52:29] - BHO 4: {77701e16-9bfe-4b63-a5b4-7bd156758a37} ()
[11/05/2006, 20:52:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:29] - No filename found. Continuing.
[11/05/2006, 20:52:29] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[11/05/2006, 20:52:29] - BHO 6: {9ED62D17-E2D3-4183-81F0-4FD0E978B194} ()
[11/05/2006, 20:52:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:29] - No filename found. Continuing.
[11/05/2006, 20:52:29] - BHO 7: {C004DEC2-2623-438e-9CA2-C9043AB28508} (ToolBar888)
[11/05/2006, 20:52:29] - BHO 8: {F18F04B0-9CF1-4b93-B004-77A288BEE28B} ()
[11/05/2006, 20:52:29] - WARNING: BHO has no default name. Checking for Winlogon reference.
[11/05/2006, 20:52:29] - Checking for HKLM\...\Winlogon\Notify\xlovduhs
[11/05/2006, 20:52:29] - Key not found: HKLM\...\Winlogon\Notify\xlovduhs, continuing.
[11/05/2006, 20:52:29] - Finished Searching Browser Helper Objects
[11/05/2006, 20:52:29] - Finishing up...
[11/05/2006, 20:52:29] - A restart is needed.
[11/05/2006, 20:52:55] - Attempting to Restart via STOP error (Blue Screen!)
[02/17/2007, 13:46:36] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/17/2007, 13:46:40] - Detected System Information:
[02/17/2007, 13:46:40] - Windows Version: 5.1.2600, Service Pack 2
[02/17/2007, 13:46:40] - Current Username: Ant (Admin)
[02/17/2007, 13:46:40] - Windows is in NORMAL mode.
[02/17/2007, 13:46:40] - Searching for Browser Helper Objects:
[02/17/2007, 13:46:40] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 13:46:40] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 13:46:40] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 13:46:40] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\nnnkhgf
[02/17/2007, 13:46:40] - Found: HKLM\...\Winlogon\Notify\nnnkhgf - This is probably Virtumundo.
[02/17/2007, 13:46:40] - Assigning {613E7B70-5380-4063-A060-C147AB994C02} MSEvents Object
[02/17/2007, 13:46:40] - BHO list has been changed! Starting over...
[02/17/2007, 13:46:40] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 13:46:40] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 13:46:40] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 13:46:40] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} (MSEvents Object)
[02/17/2007, 13:46:40] - ALERT: Found MSEvents Object!
[02/17/2007, 13:46:40] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 13:46:40] - BHO 7: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 13:46:40] - BHO 8: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - BHO 9: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 13:46:40] - BHO 10: {CFD92842-4212-438D-957F-955DF13E78EE} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\ddayv
[02/17/2007, 13:46:40] - Found: HKLM\...\Winlogon\Notify\ddayv - This is probably Virtumundo.
[02/17/2007, 13:46:40] - Assigning {CFD92842-4212-438D-957F-955DF13E78EE} MSEvents Object
[02/17/2007, 13:46:40] - BHO list has been changed! Starting over...
[02/17/2007, 13:46:40] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 13:46:40] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 13:46:40] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 13:46:40] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} (MSEvents Object)
[02/17/2007, 13:46:40] - ALERT: Found MSEvents Object!
[02/17/2007, 13:46:40] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 13:46:40] - BHO 7: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 13:46:40] - BHO 8: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - BHO 9: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 13:46:40] - BHO 10: {CFD92842-4212-438D-957F-955DF13E78EE} (MSEvents Object)
[02/17/2007, 13:46:40] - ALERT: Found MSEvents Object!
[02/17/2007, 13:46:40] - BHO 11: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/17/2007, 13:46:40] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/17/2007, 13:46:40] - BHO 12: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/17/2007, 13:46:40] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:46:40] - No filename found. Continuing.
[02/17/2007, 13:46:40] - Finished Searching Browser Helper Objects
[02/17/2007, 13:46:40] - *** Detected MSEvents Object
[02/17/2007, 13:46:40] - Trying to remove MSEvents Object...
[02/17/2007, 13:46:41] - Terminating Process: IEXPLORE.EXE
[02/17/2007, 13:46:42] - Terminating Process: RUNDLL32.EXE
[02/17/2007, 13:46:42] - Disabling Automatic Shell Restart
[02/17/2007, 13:46:42] - Terminating Process: EXPLORER.EXE
[02/17/2007, 13:46:42] - Suspending the NT Session Manager System Service
[02/17/2007, 13:46:43] - Terminating Windows NT Logon/Logoff Manager
[02/17/2007, 13:52:11] - Re-enabling Automatic Shell Restart
[02/17/2007, 13:52:11] - File to disable: C:\WINDOWS\system32\nnnkhgf.dll
[02/17/2007, 13:52:11] - Renaming C:\WINDOWS\system32\nnnkhgf.dll -> C:\WINDOWS\system32\nnnkhgf.dll.vir
[02/17/2007, 13:52:11] - File successfully renamed!
[02/17/2007, 13:52:11] - Removing HKLM\...\Browser Helper Objects\{613E7B70-5380-4063-A060-C147AB994C02}
[02/17/2007, 13:52:11] - Removing HKCR\CLSID\{613E7B70-5380-4063-A060-C147AB994C02}
[02/17/2007, 13:52:11] - Adding Kill Bit for ActiveX for GUID: {613E7B70-5380-4063-A060-C147AB994C02}
[02/17/2007, 13:52:11] - Deleting ATLEvents/MSEvents Registry entries
[02/17/2007, 13:52:11] - Removing HKLM\...\Winlogon\Notify\nnnkhgf
[02/17/2007, 13:52:11] - Searching for Browser Helper Objects:
[02/17/2007, 13:52:11] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 13:52:11] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 13:52:11] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 13:52:11] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 13:52:11] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 13:52:11] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - No filename found. Continuing.
[02/17/2007, 13:52:11] - BHO 5: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 13:52:11] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 13:52:11] - BHO 6: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 13:52:11] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 13:52:11] - BHO 7: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - No filename found. Continuing.
[02/17/2007, 13:52:11] - BHO 8: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 13:52:11] - BHO 9: {CFD92842-4212-438D-957F-955DF13E78EE} (MSEvents Object)
[02/17/2007, 13:52:11] - ALERT: Found MSEvents Object!
[02/17/2007, 13:52:11] - BHO 10: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/17/2007, 13:52:11] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/17/2007, 13:52:11] - BHO 11: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/17/2007, 13:52:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:11] - No filename found. Continuing.
[02/17/2007, 13:52:11] - Finished Searching Browser Helper Objects
[02/17/2007, 13:52:11] - *** Detected MSEvents Object
[02/17/2007, 13:52:11] - Trying to remove MSEvents Object...
[02/17/2007, 13:52:12] - Terminating Process: IEXPLORE.EXE
[02/17/2007, 13:52:12] - Terminating Process: RUNDLL32.EXE
[02/17/2007, 13:52:12] - Disabling Automatic Shell Restart
[02/17/2007, 13:52:12] - Terminating Process: EXPLORER.EXE
[02/17/2007, 13:52:12] - Suspending the NT Session Manager System Service
[02/17/2007, 13:52:13] - Terminating Windows NT Logon/Logoff Manager
[02/17/2007, 13:52:13] - Re-enabling Automatic Shell Restart
[02/17/2007, 13:52:13] - File to disable: C:\WINDOWS\system32\ddayv.dll
[02/17/2007, 13:52:13] - Renaming C:\WINDOWS\system32\ddayv.dll -> C:\WINDOWS\system32\ddayv.dll.vir
[02/17/2007, 13:52:13] - File successfully renamed!
[02/17/2007, 13:52:13] - Removing HKLM\...\Browser Helper Objects\{CFD92842-4212-438D-957F-955DF13E78EE}
[02/17/2007, 13:52:13] - Removing HKCR\CLSID\{CFD92842-4212-438D-957F-955DF13E78EE}
[02/17/2007, 13:52:13] - Adding Kill Bit for ActiveX for GUID: {CFD92842-4212-438D-957F-955DF13E78EE}
[02/17/2007, 13:52:13] - Deleting ATLEvents/MSEvents Registry entries
[02/17/2007, 13:52:13] - Removing HKLM\...\Winlogon\Notify\ddayv
[02/17/2007, 13:52:13] - Searching for Browser Helper Objects:
[02/17/2007, 13:52:13] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 13:52:13] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 13:52:13] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 13:52:13] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 13:52:13] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 13:52:13] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - No filename found. Continuing.
[02/17/2007, 13:52:13] - BHO 5: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 13:52:13] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 13:52:13] - BHO 6: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 13:52:13] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 13:52:13] - BHO 7: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - No filename found. Continuing.
[02/17/2007, 13:52:13] - BHO 8: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 13:52:13] - BHO 9: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/17/2007, 13:52:13] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/17/2007, 13:52:13] - BHO 10: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/17/2007, 13:52:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 13:52:13] - No filename found. Continuing.
[02/17/2007, 13:52:13] - Finished Searching Browser Helper Objects
[02/17/2007, 13:52:13] - Finishing up...
[02/17/2007, 13:52:13] - A restart is needed.
[02/17/2007, 14:54:49] - Attempting to Restart via STOP error (Blue Screen!)
[02/17/2007, 15:52:30] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/17/2007, 15:52:33] - Detected System Information:
[02/17/2007, 15:52:33] - Windows Version: 5.1.2600, Service Pack 2
[02/17/2007, 15:52:33] - Current Username: Administrator (Admin)
[02/17/2007, 15:52:33] - Windows is in SAFE mode with Networking.
[02/17/2007, 15:52:33] - Searching for Browser Helper Objects:
[02/17/2007, 15:52:33] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 15:52:33] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 15:52:33] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 15:52:33] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 15:52:33] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 15:52:33] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - No filename found. Continuing.
[02/17/2007, 15:52:33] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - No filename found. Continuing.
[02/17/2007, 15:52:33] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 15:52:33] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 15:52:33] - BHO 7: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 15:52:33] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:33] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 15:52:33] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 15:52:34] - BHO 8: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 15:52:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:34] - No filename found. Continuing.
[02/17/2007, 15:52:34] - BHO 9: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 15:52:34] - BHO 10: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/17/2007, 15:52:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:34] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/17/2007, 15:52:34] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/17/2007, 15:52:34] - BHO 11: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/17/2007, 15:52:34] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 15:52:34] - No filename found. Continuing.
[02/17/2007, 15:52:34] - Finished Searching Browser Helper Objects
[02/17/2007, 15:52:34] - Finishing up...
[02/17/2007, 15:52:34] - Nothing found! Exiting...
[02/17/2007, 21:33:03] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/17/2007, 21:33:04] - Detected System Information:
[02/17/2007, 21:33:04] - Windows Version: 5.1.2600, Service Pack 2
[02/17/2007, 21:33:04] - Current Username: Administrator (Admin)
[02/17/2007, 21:33:04] - Windows is in SAFE mode with Networking.
[02/17/2007, 21:33:04] - Searching for Browser Helper Objects:
[02/17/2007, 21:33:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/17/2007, 21:33:04] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/17/2007, 21:33:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:04] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/17/2007, 21:33:04] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/17/2007, 21:33:04] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/17/2007, 21:33:05] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/17/2007, 21:33:05] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - No filename found. Continuing.
[02/17/2007, 21:33:05] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - No filename found. Continuing.
[02/17/2007, 21:33:05] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/17/2007, 21:33:05] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/17/2007, 21:33:05] - BHO 7: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/17/2007, 21:33:05] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/17/2007, 21:33:05] - BHO 8: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - No filename found. Continuing.
[02/17/2007, 21:33:05] - BHO 9: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/17/2007, 21:33:05] - BHO 10: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/17/2007, 21:33:05] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/17/2007, 21:33:05] - BHO 11: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/17/2007, 21:33:05] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/17/2007, 21:33:05] - No filename found. Continuing.
[02/17/2007, 21:33:05] - Finished Searching Browser Helper Objects
[02/17/2007, 21:33:05] - Finishing up...
[02/17/2007, 21:33:05] - Nothing found! Exiting...
[02/18/2007, 15:33:17] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/18/2007, 15:33:19] - Detected System Information:
[02/18/2007, 15:33:19] - Windows Version: 5.1.2600, Service Pack 2
[02/18/2007, 15:33:19] - Current Username: Administrator (Admin)
[02/18/2007, 15:33:19] - Windows is in SAFE mode with Networking.
[02/18/2007, 15:33:19] - Searching for Browser Helper Objects:
[02/18/2007, 15:33:19] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/18/2007, 15:33:19] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/18/2007, 15:33:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:19] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/18/2007, 15:33:19] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/18/2007, 15:33:20] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:20] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/18/2007, 15:33:20] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/18/2007, 15:33:20] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:20] - No filename found. Continuing.
[02/18/2007, 15:33:20] - BHO 5: {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:20] - Checking for HKLM\...\Winlogon\Notify\urqnkkh
[02/18/2007, 15:33:20] - Found: HKLM\...\Winlogon\Notify\urqnkkh - This is probably Virtumundo.
[02/18/2007, 15:33:20] - Assigning {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} MSEvents Object
[02/18/2007, 15:33:20] - BHO list has been changed! Starting over...
[02/18/2007, 15:33:20] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/18/2007, 15:33:20] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:20] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/18/2007, 15:33:20] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/18/2007, 15:33:20] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:20] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/18/2007, 15:33:20] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/18/2007, 15:33:20] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/18/2007, 15:33:20] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:21] - No filename found. Continuing.
[02/18/2007, 15:33:21] - BHO 5: {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} (MSEvents Object)
[02/18/2007, 15:33:21] - ALERT: Found MSEvents Object!
[02/18/2007, 15:33:21] - BHO 6: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/18/2007, 15:33:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:21] - No filename found. Continuing.
[02/18/2007, 15:33:21] - BHO 7: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/18/2007, 15:33:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:21] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/18/2007, 15:33:21] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/18/2007, 15:33:21] - BHO 8: {6BA9D445-B6D6-45C5-A854-C22B271911AA} ()
[02/18/2007, 15:33:21] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:21] - Checking for HKLM\...\Winlogon\Notify\ssqrr
[02/18/2007, 15:33:21] - Found: HKLM\...\Winlogon\Notify\ssqrr - This is probably Virtumundo.
[02/18/2007, 15:33:21] - Assigning {6BA9D445-B6D6-45C5-A854-C22B271911AA} MSEvents Object
[02/18/2007, 15:33:22] - BHO list has been changed! Starting over...
[02/18/2007, 15:33:22] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/18/2007, 15:33:22] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/18/2007, 15:33:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:22] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/18/2007, 15:33:22] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/18/2007, 15:33:22] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/18/2007, 15:33:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:22] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/18/2007, 15:33:22] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/18/2007, 15:33:22] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/18/2007, 15:33:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:22] - No filename found. Continuing.
[02/18/2007, 15:33:22] - BHO 5: {58FF7395-B48F-41CB-A20C-2FFA2A049EB2} (MSEvents Object)
[02/18/2007, 15:33:22] - ALERT: Found MSEvents Object!
[02/18/2007, 15:33:22] - BHO 6: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/18/2007, 15:33:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:22] - No filename found. Continuing.
[02/18/2007, 15:33:22] - BHO 7: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/18/2007, 15:33:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:22] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/18/2007, 15:33:22] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/18/2007, 15:33:22] - BHO 8: {6BA9D445-B6D6-45C5-A854-C22B271911AA} (MSEvents Object)
[02/18/2007, 15:33:22] - ALERT: Found MSEvents Object!
[02/18/2007, 15:33:23] - BHO 9: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/18/2007, 15:33:23] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:23] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/18/2007, 15:33:23] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/18/2007, 15:33:23] - BHO 10: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/18/2007, 15:33:23] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:23] - No filename found. Continuing.
[02/18/2007, 15:33:23] - BHO 11: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/18/2007, 15:33:23] - BHO 12: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/18/2007, 15:33:23] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:23] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/18/2007, 15:33:23] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/18/2007, 15:33:23] - BHO 13: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/18/2007, 15:33:23] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:33:23] - No filename found. Continuing.
[02/18/2007, 15:33:23] - Finished Searching Browser Helper Objects
[02/18/2007, 15:33:23] - *** Detected MSEvents Object
[02/18/2007, 15:33:23] - Trying to remove MSEvents Object...
[02/18/2007, 15:33:25] - Terminating Process: IEXPLORE.EXE
[02/18/2007, 15:33:26] - Terminating Process: RUNDLL32.EXE
[02/18/2007, 15:33:26] - Disabling Automatic Shell Restart
[02/18/2007, 15:33:26] - Terminating Process: EXPLORER.EXE
[02/18/2007, 15:33:27] - Suspending the NT Session Manager System Service
[02/18/2007, 15:33:27] - Terminating Windows NT Logon/Logoff Manager
[02/18/2007, 15:38:55] - Re-enabling Automatic Shell Restart
[02/18/2007, 15:38:55] - File to disable: C:\WINDOWS\system32\urqnkkh.dll
[02/18/2007, 15:38:55] - Renaming C:\WINDOWS\system32\urqnkkh.dll -> C:\WINDOWS\system32\urqnkkh.dll.vir
[02/18/2007, 15:38:55] - File successfully renamed!
[02/18/2007, 15:38:55] - Removing HKLM\...\Browser Helper Objects\{58FF7395-B48F-41CB-A20C-2FFA2A049EB2}
[02/18/2007, 15:38:55] - Removing HKCR\CLSID\{58FF7395-B48F-41CB-A20C-2FFA2A049EB2}
[02/18/2007, 15:38:55] - Adding Kill Bit for ActiveX for GUID: {58FF7395-B48F-41CB-A20C-2FFA2A049EB2}
[02/18/2007, 15:38:55] - Deleting ATLEvents/MSEvents Registry entries
[02/18/2007, 15:38:55] - Removing HKLM\...\Winlogon\Notify\urqnkkh
[02/18/2007, 15:38:55] - Searching for Browser Helper Objects:
[02/18/2007, 15:38:55] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/18/2007, 15:38:56] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/18/2007, 15:38:56] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/18/2007, 15:38:56] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/18/2007, 15:38:56] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/18/2007, 15:38:56] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - No filename found. Continuing.
[02/18/2007, 15:38:56] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - No filename found. Continuing.
[02/18/2007, 15:38:56] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/18/2007, 15:38:56] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/18/2007, 15:38:56] - BHO 7: {6BA9D445-B6D6-45C5-A854-C22B271911AA} (MSEvents Object)
[02/18/2007, 15:38:56] - ALERT: Found MSEvents Object!
[02/18/2007, 15:38:56] - BHO 8: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/18/2007, 15:38:56] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/18/2007, 15:38:56] - BHO 9: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - No filename found. Continuing.
[02/18/2007, 15:38:56] - BHO 10: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/18/2007, 15:38:56] - BHO 11: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/18/2007, 15:38:56] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/18/2007, 15:38:56] - BHO 12: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/18/2007, 15:38:56] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:56] - No filename found. Continuing.
[02/18/2007, 15:38:56] - Finished Searching Browser Helper Objects
[02/18/2007, 15:38:56] - *** Detected MSEvents Object
[02/18/2007, 15:38:56] - Trying to remove MSEvents Object...
[02/18/2007, 15:38:57] - Terminating Process: IEXPLORE.EXE
[02/18/2007, 15:38:57] - Terminating Process: RUNDLL32.EXE
[02/18/2007, 15:38:57] - Disabling Automatic Shell Restart
[02/18/2007, 15:38:57] - Terminating Process: EXPLORER.EXE
[02/18/2007, 15:38:57] - Suspending the NT Session Manager System Service
[02/18/2007, 15:38:57] - Terminating Windows NT Logon/Logoff Manager
[02/18/2007, 15:38:58] - Re-enabling Automatic Shell Restart
[02/18/2007, 15:38:58] - File to disable: C:\WINDOWS\system32\ssqrr.dll
[02/18/2007, 15:38:58] - Renaming C:\WINDOWS\system32\ssqrr.dll -> C:\WINDOWS\system32\ssqrr.dll.vir
[02/18/2007, 15:38:58] - File successfully renamed!
[02/18/2007, 15:38:58] - Removing HKLM\...\Browser Helper Objects\{6BA9D445-B6D6-45C5-A854-C22B271911AA}
[02/18/2007, 15:38:58] - Removing HKCR\CLSID\{6BA9D445-B6D6-45C5-A854-C22B271911AA}
[02/18/2007, 15:38:58] - Adding Kill Bit for ActiveX for GUID: {6BA9D445-B6D6-45C5-A854-C22B271911AA}
[02/18/2007, 15:38:58] - Deleting ATLEvents/MSEvents Registry entries
[02/18/2007, 15:38:58] - Removing HKLM\...\Winlogon\Notify\ssqrr
[02/18/2007, 15:38:58] - Searching for Browser Helper Objects:
[02/18/2007, 15:38:58] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/18/2007, 15:38:58] - BHO 2: {0BB12649-D5A7-C516-6E29-01A0C222C039} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - Checking for HKLM\...\Winlogon\Notify\xsvebvb
[02/18/2007, 15:38:58] - Key not found: HKLM\...\Winlogon\Notify\xsvebvb, continuing.
[02/18/2007, 15:38:58] - BHO 3: {2A04CAB7-6759-4FAA-AD5E-820EFD2FA5F9} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - Checking for HKLM\...\Winlogon\Notify\jkhfe
[02/18/2007, 15:38:58] - Key not found: HKLM\...\Winlogon\Notify\jkhfe, continuing.
[02/18/2007, 15:38:58] - BHO 4: {2CE36516-16DA-4CB4-84A7-72CF9BEA721F} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - No filename found. Continuing.
[02/18/2007, 15:38:58] - BHO 5: {613E7B70-5380-4063-A060-C147AB994C02} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - No filename found. Continuing.
[02/18/2007, 15:38:58] - BHO 6: {67982BB7-0F95-44C5-92DC-E3AF3DC19D6D} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - Checking for HKLM\...\Winlogon\Notify\isadd
[02/18/2007, 15:38:58] - Key not found: HKLM\...\Winlogon\Notify\isadd, continuing.
[02/18/2007, 15:38:58] - BHO 7: {8668B413-5AD6-2C7B-8E3D-5F9090A338CE} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - Checking for HKLM\...\Winlogon\Notify\ixl
[02/18/2007, 15:38:58] - Key not found: HKLM\...\Winlogon\Notify\ixl, continuing.
[02/18/2007, 15:38:58] - BHO 8: {873EEB42-52D2-7D2C-DD3D-5F9090A338C4} ()
[02/18/2007, 15:38:58] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:58] - No filename found. Continuing.
[02/18/2007, 15:38:58] - BHO 9: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/18/2007, 15:38:58] - BHO 10: {E03C740E-BB24-4d3c-B92A-6F84DE1DD99C} ()
[02/18/2007, 15:38:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:59] - Checking for HKLM\...\Winlogon\Notify\snfcgjqm
[02/18/2007, 15:38:59] - Key not found: HKLM\...\Winlogon\Notify\snfcgjqm, continuing.
[02/18/2007, 15:38:59] - BHO 11: {EEA3185F-C1C1-4F1B-8604-9C2397CBA94D} ()
[02/18/2007, 15:38:59] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/18/2007, 15:38:59] - No filename found. Continuing.
[02/18/2007, 15:38:59] - Finished Searching Browser Helper Objects
[02/18/2007, 15:38:59] - Finishing up...
[02/18/2007, 15:38:59] - A restart is needed.
[02/18/2007, 15:39:04] - Attempting to Restart via STOP error (Blue Screen!)
[02/19/2007, 20:03:50] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/19/2007, 20:03:53] - Detected System Information:
[02/19/2007, 20:03:53] - Windows Version: 5.1.2600, Service Pack 2
[02/19/2007, 20:03:53] - Current Username: Ant (Admin)
[02/19/2007, 20:03:53] - Windows is in NORMAL mode.
[02/19/2007, 20:03:53] - Searching for Browser Helper Objects:
[02/19/2007, 20:03:53] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/19/2007, 20:03:53] - BHO 2: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/19/2007, 20:03:53] - Finished Searching Browser Helper Objects
[02/19/2007, 20:03:53] - Finishing up...
[02/19/2007, 20:03:53] - Nothing found! Exiting...
[02/19/2007, 20:04:18] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/19/2007, 20:04:20] - Detected System Information:
[02/19/2007, 20:04:20] - Windows Version: 5.1.2600, Service Pack 2
[02/19/2007, 20:04:20] - Current Username: Ant (Admin)
[02/19/2007, 20:04:20] - Windows is in NORMAL mode.
[02/19/2007, 20:04:20] - Searching for Browser Helper Objects:
[02/19/2007, 20:04:20] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/19/2007, 20:04:20] - BHO 2: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/19/2007, 20:04:20] - Finished Searching Browser Helper Objects
[02/19/2007, 20:04:20] - Finishing up...
[02/19/2007, 20:04:20] - Nothing found! Exiting...
[02/19/2007, 20:10:14] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Ant\My Documents\programs\antivirus\VirtumundoBeGone.exe" )
[02/19/2007, 20:10:22] - Detected System Information:
[02/19/2007, 20:10:22] - Windows Version: 5.1.2600, Service Pack 2
[02/19/2007, 20:10:22] - Current Username: Ant (Admin)
[02/19/2007, 20:10:22] - Windows is in NORMAL mode.
[02/19/2007, 20:10:22] - Searching for Browser Helper Objects:
[02/19/2007, 20:10:22] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (AcroIEHlprObj Class)
[02/19/2007, 20:10:22] - BHO 2: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[02/19/2007, 20:10:22] - Finished Searching Browser Helper Objects
[02/19/2007, 20:10:22] - Finishing up...
[02/19/2007, 20:10:22] - Nothing found! Exiting...