Joo eikö se oo tämä.
[03/03/2007, 14:47:57] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\jallu\Työpöytä\VirtumundoBeGone.exe" )
[03/03/2007, 14:48:06] - Detected System Information:
[03/03/2007, 14:48:06] - Windows Version: 5.1.2600, Service Pack 2
[03/03/2007, 14:48:06] - Current Username: jallu (Admin)
[03/03/2007, 14:48:06] - Windows is in NORMAL mode.
[03/03/2007, 14:48:06] - Searching for Browser Helper Objects:
[03/03/2007, 14:48:06] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/03/2007, 14:48:06] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/03/2007, 14:48:06] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\NppBho
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.
[03/03/2007, 14:48:06] - BHO 4: {3C503E1A-BB2D-7625-3CB0-0BA12C17A258} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\lcbnaxc
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\lcbnaxc, continuing.
[03/03/2007, 14:48:06] - BHO 5: {78BF8974-A9A7-47CE-A9E0-29A92DF626E2} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\khfcbxw
[03/03/2007, 14:48:06] - Found: HKLM\...\Winlogon\Notify\khfcbxw - This is probably Virtumundo.
[03/03/2007, 14:48:06] - Assigning {78BF8974-A9A7-47CE-A9E0-29A92DF626E2} MSEvents Object
[03/03/2007, 14:48:06] - BHO list has been changed! Starting over...
[03/03/2007, 14:48:06] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/03/2007, 14:48:06] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/03/2007, 14:48:06] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\NppBho
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.
[03/03/2007, 14:48:06] - BHO 4: {3C503E1A-BB2D-7625-3CB0-0BA12C17A258} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\lcbnaxc
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\lcbnaxc, continuing.
[03/03/2007, 14:48:06] - BHO 5: {78BF8974-A9A7-47CE-A9E0-29A92DF626E2} (MSEvents Object)
[03/03/2007, 14:48:06] - ALERT: Found MSEvents Object!
[03/03/2007, 14:48:06] - BHO 6: {A1C041E3-F6CC-4582-BD15-1124D9A06747} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\pmnll
[03/03/2007, 14:48:06] - Found: HKLM\...\Winlogon\Notify\pmnll - This is probably Virtumundo.
[03/03/2007, 14:48:06] - Assigning {A1C041E3-F6CC-4582-BD15-1124D9A06747} MSEvents Object
[03/03/2007, 14:48:06] - BHO list has been changed! Starting over...
[03/03/2007, 14:48:06] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/03/2007, 14:48:06] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/03/2007, 14:48:06] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\NppBho
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.
[03/03/2007, 14:48:06] - BHO 4: {3C503E1A-BB2D-7625-3CB0-0BA12C17A258} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\lcbnaxc
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\lcbnaxc, continuing.
[03/03/2007, 14:48:06] - BHO 5: {78BF8974-A9A7-47CE-A9E0-29A92DF626E2} (MSEvents Object)
[03/03/2007, 14:48:06] - ALERT: Found MSEvents Object!
[03/03/2007, 14:48:06] - BHO 6: {A1C041E3-F6CC-4582-BD15-1124D9A06747} (MSEvents Object)
[03/03/2007, 14:48:06] - ALERT: Found MSEvents Object!
[03/03/2007, 14:48:06] - BHO 7: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/03/2007, 14:48:06] - BHO 8: {B4EFE0DD-4CFA-430B-BBC3-E8FD16C45D71} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\mllml
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\mllml, continuing.
[03/03/2007, 14:48:06] - BHO 9: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/03/2007, 14:48:06] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:48:06] - Checking for HKLM\...\Winlogon\Notify\qcngfpwk
[03/03/2007, 14:48:06] - Key not found: HKLM\...\Winlogon\Notify\qcngfpwk, continuing.
[03/03/2007, 14:48:06] - BHO 10: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[03/03/2007, 14:48:06] - Finished Searching Browser Helper Objects
[03/03/2007, 14:48:06] - *** Detected MSEvents Object
[03/03/2007, 14:48:06] - Trying to remove MSEvents Object...
[03/03/2007, 14:48:07] - Terminating Process: IEXPLORE.EXE
[03/03/2007, 14:48:07] - Terminating Process: RUNDLL32.EXE
[03/03/2007, 14:48:07] - Disabling Automatic Shell Restart
[03/03/2007, 14:48:07] - Terminating Process: EXPLORER.EXE
[03/03/2007, 14:48:07] - Suspending the NT Session Manager System Service
[03/03/2007, 14:48:07] - Terminating Windows NT Logon/Logoff Manager
[03/03/2007, 14:53:09] - Re-enabling Automatic Shell Restart
[03/03/2007, 14:53:09] - File to disable: C:\WINDOWS\system32\khfcbxw.dll
[03/03/2007, 14:53:09] - Renaming C:\WINDOWS\system32\khfcbxw.dll -> C:\WINDOWS\system32\khfcbxw.dll.vir
[03/03/2007, 14:53:09] - File successfully renamed!
[03/03/2007, 14:53:09] - Removing HKLM\...\Browser Helper Objects\{78BF8974-A9A7-47CE-A9E0-29A92DF626E2}
[03/03/2007, 14:53:09] - Removing HKCR\CLSID\{78BF8974-A9A7-47CE-A9E0-29A92DF626E2}
[03/03/2007, 14:53:09] - Adding Kill Bit for ActiveX for GUID: {78BF8974-A9A7-47CE-A9E0-29A92DF626E2}
[03/03/2007, 14:53:09] - Deleting ATLEvents/MSEvents Registry entries
[03/03/2007, 14:53:09] - Removing HKLM\...\Winlogon\Notify\khfcbxw
[03/03/2007, 14:53:09] - Searching for Browser Helper Objects:
[03/03/2007, 14:53:09] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/03/2007, 14:53:09] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/03/2007, 14:53:09] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()
[03/03/2007, 14:53:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:09] - Checking for HKLM\...\Winlogon\Notify\NppBho
[03/03/2007, 14:53:09] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.
[03/03/2007, 14:53:09] - BHO 4: {3C503E1A-BB2D-7625-3CB0-0BA12C17A258} ()
[03/03/2007, 14:53:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:09] - Checking for HKLM\...\Winlogon\Notify\lcbnaxc
[03/03/2007, 14:53:09] - Key not found: HKLM\...\Winlogon\Notify\lcbnaxc, continuing.
[03/03/2007, 14:53:09] - BHO 5: {A1C041E3-F6CC-4582-BD15-1124D9A06747} (MSEvents Object)
[03/03/2007, 14:53:09] - ALERT: Found MSEvents Object!
[03/03/2007, 14:53:09] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/03/2007, 14:53:09] - BHO 7: {B4EFE0DD-4CFA-430B-BBC3-E8FD16C45D71} ()
[03/03/2007, 14:53:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:09] - Checking for HKLM\...\Winlogon\Notify\mllml
[03/03/2007, 14:53:09] - Key not found: HKLM\...\Winlogon\Notify\mllml, continuing.
[03/03/2007, 14:53:09] - BHO 8: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/03/2007, 14:53:09] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:09] - Checking for HKLM\...\Winlogon\Notify\qcngfpwk
[03/03/2007, 14:53:09] - Key not found: HKLM\...\Winlogon\Notify\qcngfpwk, continuing.
[03/03/2007, 14:53:09] - BHO 9: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[03/03/2007, 14:53:09] - Finished Searching Browser Helper Objects
[03/03/2007, 14:53:09] - *** Detected MSEvents Object
[03/03/2007, 14:53:09] - Trying to remove MSEvents Object...
[03/03/2007, 14:53:10] - Terminating Process: IEXPLORE.EXE
[03/03/2007, 14:53:10] - Terminating Process: RUNDLL32.EXE
[03/03/2007, 14:53:11] - Disabling Automatic Shell Restart
[03/03/2007, 14:53:11] - Terminating Process: EXPLORER.EXE
[03/03/2007, 14:53:11] - Suspending the NT Session Manager System Service
[03/03/2007, 14:53:11] - Terminating Windows NT Logon/Logoff Manager
[03/03/2007, 14:53:11] - Re-enabling Automatic Shell Restart
[03/03/2007, 14:53:11] - File to disable: C:\WINDOWS\system32\pmnll.dll
[03/03/2007, 14:53:11] - Renaming C:\WINDOWS\system32\pmnll.dll -> C:\WINDOWS\system32\pmnll.dll.vir
[03/03/2007, 14:53:11] - File successfully renamed!
[03/03/2007, 14:53:11] - Removing HKLM\...\Browser Helper Objects\{A1C041E3-F6CC-4582-BD15-1124D9A06747}
[03/03/2007, 14:53:11] - Removing HKCR\CLSID\{A1C041E3-F6CC-4582-BD15-1124D9A06747}
[03/03/2007, 14:53:11] - Adding Kill Bit for ActiveX for GUID: {A1C041E3-F6CC-4582-BD15-1124D9A06747}
[03/03/2007, 14:53:11] - Deleting ATLEvents/MSEvents Registry entries
[03/03/2007, 14:53:11] - Removing HKLM\...\Winlogon\Notify\pmnll
[03/03/2007, 14:53:11] - Searching for Browser Helper Objects:
[03/03/2007, 14:53:11] - BHO 1: {02478D38-C3F9-4EFB-9B51-7695ECA05670} (Yahoo! Toolbar Helper)
[03/03/2007, 14:53:11] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[03/03/2007, 14:53:11] - BHO 3: {1E8A6170-7264-4D0F-BEAE-D42A53123C75} ()
[03/03/2007, 14:53:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:11] - Checking for HKLM\...\Winlogon\Notify\NppBho
[03/03/2007, 14:53:11] - Key not found: HKLM\...\Winlogon\Notify\NppBho, continuing.
[03/03/2007, 14:53:11] - BHO 4: {3C503E1A-BB2D-7625-3CB0-0BA12C17A258} ()
[03/03/2007, 14:53:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:11] - Checking for HKLM\...\Winlogon\Notify\lcbnaxc
[03/03/2007, 14:53:11] - Key not found: HKLM\...\Winlogon\Notify\lcbnaxc, continuing.
[03/03/2007, 14:53:11] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[03/03/2007, 14:53:11] - BHO 6: {B4EFE0DD-4CFA-430B-BBC3-E8FD16C45D71} ()
[03/03/2007, 14:53:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:11] - Checking for HKLM\...\Winlogon\Notify\mllml
[03/03/2007, 14:53:11] - Key not found: HKLM\...\Winlogon\Notify\mllml, continuing.
[03/03/2007, 14:53:11] - BHO 7: {D38439EC-4A7F-42b4-90C2-D810D7778FDD} ()
[03/03/2007, 14:53:11] - WARNING: BHO has no default name. Checking for Winlogon reference.
[03/03/2007, 14:53:11] - Checking for HKLM\...\Winlogon\Notify\qcngfpwk
[03/03/2007, 14:53:11] - Key not found: HKLM\...\Winlogon\Notify\qcngfpwk, continuing.
[03/03/2007, 14:53:11] - BHO 8: {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} (EpsonToolBandKicker Class)
[03/03/2007, 14:53:11] - Finished Searching Browser Helper Objects
[03/03/2007, 14:53:11] - Finishing up...
[03/03/2007, 14:53:11] - A restart is needed.
[03/03/2007, 16:48:19] - Attempting to Restart via STOP error (Blue Screen!)
jallu79
|