[03/24/2008, 3:35:25] - Detected System Information:
[03/24/2008, 3:35:25] - Windows Version: 5.1.2600, Service Pack 2
[03/24/2008, 3:35:25] - Current Username: Crisp Beatz (Admin)
[03/24/2008, 3:35:25] - Windows is in NORMAL mode.
[03/24/2008, 3:35:25] - Searching for Browser Helper Objects:
[03/24/2008, 3:35:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/24/2008, 3:35:25] - BHO 2: {45C2A50F-8F4A-496E-AF02-D0207525BF5A} ()
[03/24/2008, 3:35:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/24/2008, 3:35:25] - Checking for HKLM\...\Winlogon\Notify\awttrst
[03/24/2008, 3:35:25] - Found: HKLM\...\Winlogon\Notify\awttrst - This is probably Virtumundo.
[03/24/2008, 3:35:25] - Assigning {45C2A50F-8F4A-496E-AF02-D0207525BF5A} MSEvents Object
[03/24/2008, 3:35:25] - BHO list has been changed! Starting over...
[03/24/2008, 3:35:25] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/24/2008, 3:35:25] - BHO 2: {45C2A50F-8F4A-496E-AF02-D0207525BF5A} (MSEvents Object)
[03/24/2008, 3:35:25] - ALERT: Found MSEvents Object!
[03/24/2008, 3:35:25] - BHO 3: {4BA1C8DC-D025-41E5-9F3F-BB085E8E3654} ()
[03/24/2008, 3:35:25] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/24/2008, 3:35:25] - Checking for HKLM\...\Winlogon\Notify\gebyx
[03/24/2008, 3:35:25] - Key not found: HKLM\...\Winlogon\Notify\gebyx, continuing.
[03/24/2008, 3:35:25] - Finished Searching Browser Helper Objects
[03/24/2008, 3:35:25] - *** Detected MSEvents Object
[03/24/2008, 3:35:25] - Trying to remove MSEvents Object...
[03/24/2008, 3:35:26] - Terminating Process: IEXPLORE.EXE
[03/24/2008, 3:35:27] - Terminating Process: RUNDLL32.EXE
[03/24/2008, 3:35:27] - Disabling Automatic Shell Restart
[03/24/2008, 3:35:27] - Terminating Process: EXPLORER.EXE
[03/24/2008, 3:35:27] - Suspending the NT Session Manager System Service
[03/24/2008, 3:35:27] - Terminating Windows NT Logon/Logoff Manager
[03/24/2008, 3:35:27] - Re-enabling Automatic Shell Restart
[03/24/2008, 3:35:27] - File to disable: E:\WINDOWS\system32\awttrst.dll
[03/24/2008, 3:35:27] - Renaming E:\WINDOWS\system32\awttrst.dll -> E:\WINDOWS\system32\awttrst.dll.vir
[03/24/2008, 3:35:28] - File successfully renamed!
[03/24/2008, 3:35:28] - Removing HKLM\...\Browser Helper Objects\{45C2A50F-8F4A-496E-AF02-D0207525BF5A}
[03/24/2008, 3:35:28] - Removing HKCR\CLSID\{45C2A50F-8F4A-496E-AF02-D0207525BF5A}
[03/24/2008, 3:35:28] - Adding Kill Bit for ActiveX for GUID: {45C2A50F-8F4A-496E-AF02-D0207525BF5A}
[03/24/2008, 3:35:28] - Deleting ATLEvents/MSEvents Registry entries
[03/24/2008, 3:35:28] - Removing HKLM\...\Winlogon\Notify\awttrst
[03/24/2008, 3:35:28] - Searching for Browser Helper Objects:
[03/24/2008, 3:35:28] - BHO 1: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/24/2008, 3:35:28] - BHO 2: {4BA1C8DC-D025-41E5-9F3F-BB085E8E3654} ()
[03/24/2008, 3:35:28] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/24/2008, 3:35:28] - Checking for HKLM\...\Winlogon\Notify\gebyx
[03/24/2008, 3:35:28] - Key not found: HKLM\...\Winlogon\Notify\gebyx, continuing.
[03/24/2008, 3:35:28] - Finished Searching Browser Helper Objects
[03/24/2008, 3:35:28] - Finishing up...
[03/24/2008, 3:35:28] - A restart is needed.
[03/24/2008, 3:35:55] - Attempting to Restart via STOP error (Blue Screen!)
thank you for any help u offer in advance