Here we go I did everything you asked.
HJT LOG:
C:\Program Files\QuickTime\qttask.exe
C:\progra~1\valve\steam\steam.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\ewido anti-malware\ewidoctrl.exe
C:\Program Files\Norton AntiVirus\navapsvc.exe
C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
C:\Program Files\Yahoo!\Messenger\ymsgr_tray.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Program Files\Messenger\msmsgs.exe
C:\hijackthis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://g.msn.com/0SEENUS/SAOS01R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext =
http://windowsupdate.microsoft.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O4 - HKLM\..\Run: [InCD] C:\Program Files\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\HP\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [Steam] "c:\progra~1\valve\steam\steam.exe" -silent
O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Download All by FlashGet - C:\Program Files\FlashGet\jc_all.htm
O8 - Extra context menu item: Download using FlashGet - C:\Program Files\FlashGet\jc_link.htm
O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) -
http://messenger.zon...kr.cab31267.cabO16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {288C5F13-7E52-4ADA-A32E-F5BF9D125F99} (CR64Loader Object) -
http://www.miniclip....pGameLoader.dllO16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) -
http://messenger.zon...er.cab31267.cabO16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) -
http://www.fileplane...DC_1_0_0_44.cabO16 - DPF: {88D758A3-D33B-45FD-91E3-67749B4057FA} -
http://dm.screensave.../sinstaller.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
http://messenger.zon...nt.cab31267.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) -
http://cdn2.zone.msn...ro.cab34246.cabO16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) -
http://zone.msn.com/...aploader_v6.cabO16 - DPF: {E5D419D6-A846-4514-9FAD-97E826C84822} (HeartbeatCtl Class) -
http://fdl.msn.com/z...s/heartbeat.cabO16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) -
http://messenger.zon...wn.cab31267.cabO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Program Files\ewido anti-malware\ewidoctrl.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Ahead Software AG - C:\Program Files\Ahead\InCD\InCDsrv.exe
O23 - Service: Norton AntiVirus Auto-Protect Service (navapsvc) - Symantec Corporation - C:\Program Files\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton AntiVirus Firewall Monitor Service (NPFMntor) - Symantec Corporation - C:\Program Files\Norton AntiVirus\IWP\NPFMntor.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Program Files\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\COMMON~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe
O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SPBBC\SPBBCSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe
Ewido Log:
---------------------------------------------------------
ewido anti-malware - Scan report
---------------------------------------------------------
+ Created on: 5:50:23 PM, 12/28/2005
+ Report-Checksum: E4DF519A
+ Scan result:
:mozilla.22:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.23:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.31:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.35:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.36:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.37:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Mediaplex : Cleaned with backup
:mozilla.39:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.40:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.41:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.58:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.59:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.60:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.61:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.63:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.67:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.68:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.69:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.70:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.71:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.72:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.73:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.74:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.75:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.76:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.77:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.89:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.90:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.91:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.93:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.95:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.96:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.97:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.98:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.99:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.114:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.115:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.118:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookies.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
:mozilla.11:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.12:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Falkag : Cleaned with backup
:mozilla.20:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.21:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Pointroll : Cleaned with backup
:mozilla.25:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Doubleclick : Cleaned with backup
:mozilla.27:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.28:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.29:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.30:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.31:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.32:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Fastclick : Cleaned with backup
:mozilla.46:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.47:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.48:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.49:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.50:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.51:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.52:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.53:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.54:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.55:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.56:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Yieldmanager : Cleaned with backup
:mozilla.68:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.69:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.70:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Advertising : Cleaned with backup
:mozilla.72:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Atdmt : Cleaned with backup
:mozilla.75:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.77:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.78:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.79:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Casalemedia : Cleaned with backup
:mozilla.80:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.81:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Targetnet : Cleaned with backup
:mozilla.84:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.85:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Com : Cleaned with backup
:mozilla.111:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Questionmarket : Cleaned with backup
:mozilla.112:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Serving-sys : Cleaned with backup
:mozilla.115:C:\Documents and Settings\USER\Application Data\Mozilla\Firefox\Profiles\2igqfbyu.default\cookiesnew.txt -> Spyware.Cookie.Trafficmp : Cleaned with backup
C:\Program Files\softnyx\GunboundWC\GunBound.gme -> Backdoor.Agobot.agh : Cleaned with backup
::Report End
VBG Log:
[12/28/2005, 18:05:29] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\USER\Desktop\VirtumundoBeGone.exe" )
[12/28/2005, 18:05:35] - Detected System Information:
[12/28/2005, 18:05:35] - Windows Version: 5.1.2600, Service Pack 2
[12/28/2005, 18:05:35] - Current Username: USER (Admin)
[12/28/2005, 18:05:35] - Windows is in NORMAL mode.
[12/28/2005, 18:05:35] - Searching for Browser Helper Objects:
[12/28/2005, 18:05:35] - BHO 1: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/28/2005, 18:05:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/28/2005, 18:05:35] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/28/2005, 18:05:35] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/28/2005, 18:05:35] - BHO 2: {93C6313C-9DB4-4694-8BD0-E378C573A9AD} (ATLDistrib Object)
[12/28/2005, 18:05:35] - ALERT: Found ATLDistrib Object!
[12/28/2005, 18:05:35] - BHO 3: {A5366673-E8CA-11D3-9CD9-0090271D075B} (IeCatch2 Class)
[12/28/2005, 18:05:35] - Finished Searching Browser Helper Objects
[12/28/2005, 18:05:35] - *** Detected ATLDistrib Object
[12/28/2005, 18:05:35] - Trying to remove ATLDistrib Object...
[12/28/2005, 18:05:36] - Terminating Process: IEXPLORE.EXE
[12/28/2005, 18:05:36] - Terminating Process: RUNDLL32.EXE
[12/28/2005, 18:05:36] - Disabling Automatic Shell Restart
[12/28/2005, 18:05:36] - Terminating Process: EXPLORER.EXE
[12/28/2005, 18:05:37] - Suspending the NT Session Manager System Service
[12/28/2005, 18:05:37] - Terminating Windows NT Logon/Logoff Manager
[12/28/2005, 18:05:37] - Re-enabling Automatic Shell Restart
[12/28/2005, 18:05:37] - File to disable: C:\WINDOWS\system32\sstts.dll
[12/28/2005, 18:05:37] - Renaming C:\WINDOWS\system32\sstts.dll -> C:\WINDOWS\system32\sstts.dll.vir
[12/28/2005, 18:05:37] - File successfully renamed!
[12/28/2005, 18:05:37] - Removing HKLM\...\Browser Helper Objects\{93C6313C-9DB4-4694-8BD0-E378C573A9AD}
[12/28/2005, 18:05:37] - Removing HKCR\CLSID\{93C6313C-9DB4-4694-8BD0-E378C573A9AD}
[12/28/2005, 18:05:37] - Adding Kill Bit for ActiveX for GUID: {93C6313C-9DB4-4694-8BD0-E378C573A9AD}
[12/28/2005, 18:05:37] - Deleting ATLEvents/MSEvents Registry entries
[12/28/2005, 18:05:37] - Removing HKLM\...\Winlogon\Notify\sstts
[12/28/2005, 18:05:37] - Searching for Browser Helper Objects:
[12/28/2005, 18:05:37] - BHO 1: {53707962-6F74-2D53-2644-206D7942484F} ()
[12/28/2005, 18:05:37] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/28/2005, 18:05:37] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[12/28/2005, 18:05:37] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[12/28/2005, 18:05:37] - BHO 2: {A5366673-E8CA-11D3-9CD9-0090271D075B} (IeCatch2 Class)
[12/28/2005, 18:05:37] - Finished Searching Browser Helper Objects
[12/28/2005, 18:05:37] - Finishing up...
[12/28/2005, 18:05:37] - A restart is needed.
[12/28/2005, 18:05:53] - Attempting to Restart via STOP error (Blue Screen!)