[12/15/2008, 15:07:58] - VirtumundoBeGone v1.5 ( "E:\VirtumundoBeGone.exe" )
[12/15/2008, 15:08:06] - Detected System Information:
[12/15/2008, 15:08:06] - Windows Version: 5.1.2600, Service Pack 3
[12/15/2008, 15:08:06] - Current Username: Administrator (Admin)
[12/15/2008, 15:08:06] - Windows is in SAFE mode with Networking.
[12/15/2008, 15:08:06] - Searching for Browser Helper Objects:
[12/15/2008, 15:08:06] - BHO 1: {053F9267-DC04-4294-A72C-58F732D338C0} (HP Print Clips)
[12/15/2008, 15:08:06] - BHO 2: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} ()
[12/15/2008, 15:08:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2008, 15:08:06] - Checking for HKLM\...\Winlogon\Notify\ljJBsQkH
[12/15/2008, 15:08:06] - Found: HKLM\...\Winlogon\Notify\ljJBsQkH - This is probably Virtumundo.
[12/15/2008, 15:08:06] - Assigning {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} MSEvents Object
[12/15/2008, 15:08:06] - BHO list has been changed! Starting over...
[12/15/2008, 15:08:06] - BHO 1: {053F9267-DC04-4294-A72C-58F732D338C0} (HP Print Clips)
[12/15/2008, 15:08:06] - BHO 2: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C} (MSEvents Object)
[12/15/2008, 15:08:06] - ALERT: Found MSEvents Object!
[12/15/2008, 15:08:06] - BHO 3: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/15/2008, 15:08:06] - BHO 4: {77AB59B4-55A3-4737-9FD5-B93C6430BF78} ()
[12/15/2008, 15:08:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2008, 15:08:06] - Checking for HKLM\...\Winlogon\Notify\dnrqprna
[12/15/2008, 15:08:06] - Key not found: HKLM\...\Winlogon\Notify\dnrqprna, continuing.
[12/15/2008, 15:08:06] - BHO 5: {F9209B2E-9129-4CFD-B2A7-9DDCC9D75B2D} ()
[12/15/2008, 15:08:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2008, 15:08:06] - Checking for HKLM\...\Winlogon\Notify\byXPjGWo
[12/15/2008, 15:08:06] - Key not found: HKLM\...\Winlogon\Notify\byXPjGWo, continuing.
[12/15/2008, 15:08:06] - Finished Searching Browser Helper Objects
[12/15/2008, 15:08:06] - *** Detected MSEvents Object
[12/15/2008, 15:08:06] - Trying to remove MSEvents Object...
[12/15/2008, 15:08:07] - Terminating Process: IEXPLORE.EXE
[12/15/2008, 15:08:07] - Terminating Process: RUNDLL32.EXE
[12/15/2008, 15:08:07] - Disabling Automatic Shell Restart
[12/15/2008, 15:08:07] - Terminating Process: EXPLORER.EXE
[12/15/2008, 15:08:08] - Suspending the NT Session Manager System Service
[12/15/2008, 15:08:08] - Terminating Windows NT Logon/Logoff Manager
[12/15/2008, 15:08:08] - Re-enabling Automatic Shell Restart
[12/15/2008, 15:08:08] - File to disable: C:\WINDOWS\system32\ljJBsQkH.dll
[12/15/2008, 15:08:08] - Renaming C:\WINDOWS\system32\ljJBsQkH.dll -> C:\WINDOWS\system32\ljJBsQkH.dll.vir
[12/15/2008, 15:08:08] - File successfully renamed!
[12/15/2008, 15:08:08] - Removing HKLM\...\Browser Helper Objects\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
[12/15/2008, 15:08:08] - Removing HKCR\CLSID\{6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
[12/15/2008, 15:08:08] - Adding Kill Bit for ActiveX for GUID: {6D794CB4-C7CD-4c6f-BFDC-9B77AFBDC02C}
[12/15/2008, 15:08:08] - Deleting ATLEvents/MSEvents Registry entries
[12/15/2008, 15:08:08] - Removing HKLM\...\Winlogon\Notify\ljJBsQkH
[12/15/2008, 15:08:08] - Searching for Browser Helper Objects:
[12/15/2008, 15:08:08] - BHO 1: {053F9267-DC04-4294-A72C-58F732D338C0} (HP Print Clips)
[12/15/2008, 15:08:08] - BHO 2: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[12/15/2008, 15:08:08] - BHO 3: {77AB59B4-55A3-4737-9FD5-B93C6430BF78} ()
[12/15/2008, 15:08:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2008, 15:08:08] - Checking for HKLM\...\Winlogon\Notify\dnrqprna
[12/15/2008, 15:08:08] - Key not found: HKLM\...\Winlogon\Notify\dnrqprna, continuing.
[12/15/2008, 15:08:08] - BHO 4: {F9209B2E-9129-4CFD-B2A7-9DDCC9D75B2D} ()
[12/15/2008, 15:08:08] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/15/2008, 15:08:08] - Checking for HKLM\...\Winlogon\Notify\byXPjGWo
[12/15/2008, 15:08:08] - Key not found: HKLM\...\Winlogon\Notify\byXPjGWo, continuing.
[12/15/2008, 15:08:08] - Finished Searching Browser Helper Objects
[12/15/2008, 15:08:08] - Finishing up...
[12/15/2008, 15:08:08] - A restart is needed.
[12/15/2008, 15:08:08] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[12/15/2008, 15:08:36] - Attempting to Restart via STOP error (Blue Screen!)
Edited by antonio770, 15 December 2008 - 03:47 PM.