Here's my VBG.txt:
[02/12/2008, 9:54:44] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Izod\Desktop\VirtumundoBeGone.exe" )
[02/12/2008, 9:55:04] - Detected System Information:
[02/12/2008, 9:55:04] - Windows Version: 5.1.2600, Service Pack 2
[02/12/2008, 9:55:04] - Current Username: Izod (Admin)
[02/12/2008, 9:55:04] - Windows is in NORMAL mode.
[02/12/2008, 9:55:04] - Searching for Browser Helper Objects:
[02/12/2008, 9:55:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/12/2008, 9:55:04] - BHO 2: {2659EC03-C1D0-4944-AA76-E02749D48836} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vturq
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[02/12/2008, 9:55:04] - BHO 3: {35aa8a7a-dcb6-426d-b8b3-c539ffa22de3} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\pwaxkfuu
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\pwaxkfuu, continuing.
[02/12/2008, 9:55:04] - BHO 4: {3E30A85B-B0B4-427C-A4D5-C8B95BB91F4C} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vtsqn
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vtsqn, continuing.
[02/12/2008, 9:55:04] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/12/2008, 9:55:04] - BHO 6: {74F62C70-870B-47FB-92CB-7CE5CF83F148} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/12/2008, 9:55:04] - BHO 8: {82EC6A5F-4602-43DA-8199-F19AF383AB1D} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 9: {9E6A2BEE-2283-4ECD-9A4A-379ACD16385E} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 10: {A95B2816-1D7E-4561-A202-68C0DE02353A} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\rdlnihhz
[02/12/2008, 9:55:04] - Found: HKLM\...\Winlogon\Notify\rdlnihhz - This is probably Virtumundo.
[02/12/2008, 9:55:04] - Assigning {A95B2816-1D7E-4561-A202-68C0DE02353A} MSEvents Object
[02/12/2008, 9:55:04] - BHO list has been changed! Starting over...
[02/12/2008, 9:55:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/12/2008, 9:55:04] - BHO 2: {2659EC03-C1D0-4944-AA76-E02749D48836} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vturq
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[02/12/2008, 9:55:04] - BHO 3: {35aa8a7a-dcb6-426d-b8b3-c539ffa22de3} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\pwaxkfuu
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\pwaxkfuu, continuing.
[02/12/2008, 9:55:04] - BHO 4: {3E30A85B-B0B4-427C-A4D5-C8B95BB91F4C} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vtsqn
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vtsqn, continuing.
[02/12/2008, 9:55:04] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/12/2008, 9:55:04] - BHO 6: {74F62C70-870B-47FB-92CB-7CE5CF83F148} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/12/2008, 9:55:04] - BHO 8: {82EC6A5F-4602-43DA-8199-F19AF383AB1D} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 9: {9E6A2BEE-2283-4ECD-9A4A-379ACD16385E} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 10: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[02/12/2008, 9:55:04] - ALERT: Found MSEvents Object!
[02/12/2008, 9:55:04] - BHO 11: {AF140986-43A6-48AF-A63B-D747AE090811} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 12: {B9E85D85-F6EE-4655-A639-E33983612A6E} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vtusqol
[02/12/2008, 9:55:04] - Found: HKLM\...\Winlogon\Notify\vtusqol - This is probably Virtumundo.
[02/12/2008, 9:55:04] - Assigning {B9E85D85-F6EE-4655-A639-E33983612A6E} MSEvents Object
[02/12/2008, 9:55:04] - BHO list has been changed! Starting over...
[02/12/2008, 9:55:04] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/12/2008, 9:55:04] - BHO 2: {2659EC03-C1D0-4944-AA76-E02749D48836} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vturq
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[02/12/2008, 9:55:04] - BHO 3: {35aa8a7a-dcb6-426d-b8b3-c539ffa22de3} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\pwaxkfuu
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\pwaxkfuu, continuing.
[02/12/2008, 9:55:04] - BHO 4: {3E30A85B-B0B4-427C-A4D5-C8B95BB91F4C} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - Checking for HKLM\...\Winlogon\Notify\vtsqn
[02/12/2008, 9:55:04] - Key not found: HKLM\...\Winlogon\Notify\vtsqn, continuing.
[02/12/2008, 9:55:04] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/12/2008, 9:55:04] - BHO 6: {74F62C70-870B-47FB-92CB-7CE5CF83F148} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/12/2008, 9:55:04] - BHO 8: {82EC6A5F-4602-43DA-8199-F19AF383AB1D} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 9: {9E6A2BEE-2283-4ECD-9A4A-379ACD16385E} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 10: {A95B2816-1D7E-4561-A202-68C0DE02353A} (MSEvents Object)
[02/12/2008, 9:55:04] - ALERT: Found MSEvents Object!
[02/12/2008, 9:55:04] - BHO 11: {AF140986-43A6-48AF-A63B-D747AE090811} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - BHO 12: {B9E85D85-F6EE-4655-A639-E33983612A6E} (MSEvents Object)
[02/12/2008, 9:55:04] - ALERT: Found MSEvents Object!
[02/12/2008, 9:55:04] - BHO 13: {F7D8C66A-B614-4E7B-8781-B8AF725CFB5F} ()
[02/12/2008, 9:55:04] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:04] - No filename found. Continuing.
[02/12/2008, 9:55:04] - Finished Searching Browser Helper Objects
[02/12/2008, 9:55:04] - *** Detected MSEvents Object
[02/12/2008, 9:55:04] - Trying to remove MSEvents Object...
[02/12/2008, 9:55:05] - Terminating Process: IEXPLORE.EXE
[02/12/2008, 9:55:05] - Terminating Process: RUNDLL32.EXE
[02/12/2008, 9:55:06] - Disabling Automatic Shell Restart
[02/12/2008, 9:55:06] - Terminating Process: EXPLORER.EXE
[02/12/2008, 9:55:06] - Suspending the NT Session Manager System Service
[02/12/2008, 9:55:07] - Terminating Windows NT Logon/Logoff Manager
[02/12/2008, 9:55:08] - Re-enabling Automatic Shell Restart
[02/12/2008, 9:55:08] - File to disable: C:\WINDOWS\system32\rdlnihhz.dll
[02/12/2008, 9:55:08] - Renaming C:\WINDOWS\system32\rdlnihhz.dll -> C:\WINDOWS\system32\rdlnihhz.dll.vir
[02/12/2008, 9:55:08] - ! File rename was unsucessful.
[02/12/2008, 9:55:08] - Attempting to Deny Access to C:\WINDOWS\system32\rdlnihhz.dll
[02/12/2008, 9:55:08] - *** IMPORTANT: Delete/Rename/Move on reboot (like Killbox) MAY NOT work.
[02/12/2008, 9:55:08] - processed file: C:\WINDOWS\system32\rdlnihhz.dll
[02/12/2008, 9:55:08] - *** IMPORTANT: The file is disabled and will need to be deleted by the user.
[02/12/2008, 9:55:08] - Removing HKLM\...\Browser Helper Objects\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[02/12/2008, 9:55:09] - Removing HKCR\CLSID\{A95B2816-1D7E-4561-A202-68C0DE02353A}
[02/12/2008, 9:55:10] - Adding Kill Bit for ActiveX for GUID: {A95B2816-1D7E-4561-A202-68C0DE02353A}
[02/12/2008, 9:55:10] - Deleting ATLEvents/MSEvents Registry entries
[02/12/2008, 9:55:10] - Removing HKLM\...\Winlogon\Notify\rdlnihhz
[02/12/2008, 9:55:10] - Searching for Browser Helper Objects:
[02/12/2008, 9:55:10] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/12/2008, 9:55:10] - BHO 2: {2659EC03-C1D0-4944-AA76-E02749D48836} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - Checking for HKLM\...\Winlogon\Notify\vturq
[02/12/2008, 9:55:10] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[02/12/2008, 9:55:10] - BHO 3: {35aa8a7a-dcb6-426d-b8b3-c539ffa22de3} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - Checking for HKLM\...\Winlogon\Notify\pwaxkfuu
[02/12/2008, 9:55:10] - Key not found: HKLM\...\Winlogon\Notify\pwaxkfuu, continuing.
[02/12/2008, 9:55:10] - BHO 4: {3E30A85B-B0B4-427C-A4D5-C8B95BB91F4C} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - Checking for HKLM\...\Winlogon\Notify\vtsqn
[02/12/2008, 9:55:10] - Key not found: HKLM\...\Winlogon\Notify\vtsqn, continuing.
[02/12/2008, 9:55:10] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/12/2008, 9:55:10] - BHO 6: {74F62C70-870B-47FB-92CB-7CE5CF83F148} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - No filename found. Continuing.
[02/12/2008, 9:55:10] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/12/2008, 9:55:10] - BHO 8: {82EC6A5F-4602-43DA-8199-F19AF383AB1D} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - No filename found. Continuing.
[02/12/2008, 9:55:10] - BHO 9: {9E6A2BEE-2283-4ECD-9A4A-379ACD16385E} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - No filename found. Continuing.
[02/12/2008, 9:55:10] - BHO 10: {AF140986-43A6-48AF-A63B-D747AE090811} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - No filename found. Continuing.
[02/12/2008, 9:55:10] - BHO 11: {B9E85D85-F6EE-4655-A639-E33983612A6E} (MSEvents Object)
[02/12/2008, 9:55:10] - ALERT: Found MSEvents Object!
[02/12/2008, 9:55:10] - BHO 12: {F7D8C66A-B614-4E7B-8781-B8AF725CFB5F} ()
[02/12/2008, 9:55:10] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:10] - No filename found. Continuing.
[02/12/2008, 9:55:10] - Finished Searching Browser Helper Objects
[02/12/2008, 9:55:10] - *** Detected MSEvents Object
[02/12/2008, 9:55:10] - Trying to remove MSEvents Object...
[02/12/2008, 9:55:11] - Terminating Process: IEXPLORE.EXE
[02/12/2008, 9:55:11] - Terminating Process: RUNDLL32.EXE
[02/12/2008, 9:55:11] - Disabling Automatic Shell Restart
[02/12/2008, 9:55:11] - Terminating Process: EXPLORER.EXE
[02/12/2008, 9:55:11] - Suspending the NT Session Manager System Service
[02/12/2008, 9:55:11] - Terminating Windows NT Logon/Logoff Manager
[02/12/2008, 9:55:12] - Re-enabling Automatic Shell Restart
[02/12/2008, 9:55:12] - File to disable: C:\WINDOWS\system32\vtusqol.dll
[02/12/2008, 9:55:12] - Renaming C:\WINDOWS\system32\vtusqol.dll -> C:\WINDOWS\system32\vtusqol.dll.vir
[02/12/2008, 9:55:12] - ! File rename was unsucessful.
[02/12/2008, 9:55:12] - Attempting to Deny Access to C:\WINDOWS\system32\vtusqol.dll
[02/12/2008, 9:55:12] - *** IMPORTANT: Delete/Rename/Move on reboot (like Killbox) MAY NOT work.
[02/12/2008, 9:55:12] - ERROR: The system cannot find the file specified.
[02/12/2008, 9:55:12] - *** IMPORTANT: The file is disabled and will need to be deleted by the user.
[02/12/2008, 9:55:12] - Removing HKLM\...\Browser Helper Objects\{B9E85D85-F6EE-4655-A639-E33983612A6E}
[02/12/2008, 9:55:12] - Removing HKCR\CLSID\{B9E85D85-F6EE-4655-A639-E33983612A6E}
[02/12/2008, 9:55:12] - Adding Kill Bit for ActiveX for GUID: {B9E85D85-F6EE-4655-A639-E33983612A6E}
[02/12/2008, 9:55:12] - Deleting ATLEvents/MSEvents Registry entries
[02/12/2008, 9:55:12] - Removing HKLM\...\Winlogon\Notify\vtusqol
[02/12/2008, 9:55:12] - Searching for Browser Helper Objects:
[02/12/2008, 9:55:12] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[02/12/2008, 9:55:12] - BHO 2: {2659EC03-C1D0-4944-AA76-E02749D48836} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - Checking for HKLM\...\Winlogon\Notify\vturq
[02/12/2008, 9:55:12] - Key not found: HKLM\...\Winlogon\Notify\vturq, continuing.
[02/12/2008, 9:55:12] - BHO 3: {35aa8a7a-dcb6-426d-b8b3-c539ffa22de3} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - Checking for HKLM\...\Winlogon\Notify\pwaxkfuu
[02/12/2008, 9:55:12] - Key not found: HKLM\...\Winlogon\Notify\pwaxkfuu, continuing.
[02/12/2008, 9:55:12] - BHO 4: {3E30A85B-B0B4-427C-A4D5-C8B95BB91F4C} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - Checking for HKLM\...\Winlogon\Notify\vtsqn
[02/12/2008, 9:55:12] - Key not found: HKLM\...\Winlogon\Notify\vtsqn, continuing.
[02/12/2008, 9:55:12] - BHO 5: {53707962-6F74-2D53-2644-206D7942484F} (Spybot-S&D IE Protection)
[02/12/2008, 9:55:12] - BHO 6: {74F62C70-870B-47FB-92CB-7CE5CF83F148} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - No filename found. Continuing.
[02/12/2008, 9:55:12] - BHO 7: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[02/12/2008, 9:55:12] - BHO 8: {82EC6A5F-4602-43DA-8199-F19AF383AB1D} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - No filename found. Continuing.
[02/12/2008, 9:55:12] - BHO 9: {9E6A2BEE-2283-4ECD-9A4A-379ACD16385E} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - No filename found. Continuing.
[02/12/2008, 9:55:12] - BHO 10: {AF140986-43A6-48AF-A63B-D747AE090811} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - No filename found. Continuing.
[02/12/2008, 9:55:12] - BHO 11: {F7D8C66A-B614-4E7B-8781-B8AF725CFB5F} ()
[02/12/2008, 9:55:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[02/12/2008, 9:55:12] - No filename found. Continuing.
[02/12/2008, 9:55:12] - Finished Searching Browser Helper Objects
[02/12/2008, 9:55:12] - Finishing up...
[02/12/2008, 9:55:12] - A restart is needed.
Edited by Izod517, 12 February 2008 - 10:06 AM.