Voici le rapport vbg.txt
[12/30/2008, 19:41:57] - VirtumundoBeGone v1.5 ( "C:\Documents and Settings\Admin\Bureau\VirtumundoBeGone.exe" )
[12/30/2008, 19:42:00] - Detected System Information:
[12/30/2008, 19:42:00] - Windows Version: 5.1.2600, Service Pack 2
[12/30/2008, 19:42:00] - Current Username: Admin (Admin)
[12/30/2008, 19:42:00] - Windows is in NORMAL mode.
[12/30/2008, 19:42:00] - Searching for Browser Helper Objects:
[12/30/2008, 19:42:00] - BHO 1: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} (Ask Search Assistant BHO)
[12/30/2008, 19:42:00] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[12/30/2008, 19:42:00] - BHO 3: {3964D8D6-86D0-493A-B460-A805B5401114} ()
[12/30/2008, 19:42:00] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/30/2008, 19:42:00] - Checking for HKLM\...\Winlogon\Notify\vtuvvvv
[12/30/2008, 19:42:00] - Found: HKLM\...\Winlogon\Notify\vtuvvvv - This is probably Virtumundo.
[12/30/2008, 19:42:00] - Assigning {3964D8D6-86D0-493A-B460-A805B5401114} MSEvents Object
[12/30/2008, 19:42:00] - BHO list has been changed! Starting over...
[12/30/2008, 19:42:00] - BHO 1: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} (Ask Search Assistant BHO)
[12/30/2008, 19:42:00] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[12/30/2008, 19:42:00] - BHO 3: {3964D8D6-86D0-493A-B460-A805B5401114} (MSEvents Object)
[12/30/2008, 19:42:00] - ALERT: Found MSEvents Object!
[12/30/2008, 19:42:00] - BHO 4: {6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4} ()
[12/30/2008, 19:42:00] - WARNING: BHO has no default name. Checking for Winlogon reference.
[12/30/2008, 19:42:00] - Checking for HKLM\...\Winlogon\Notify\pmnli
[12/30/2008, 19:42:00] - Found: HKLM\...\Winlogon\Notify\pmnli - This is probably Virtumundo.
[12/30/2008, 19:42:00] - Assigning {6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4} MSEvents Object
[12/30/2008, 19:42:00] - BHO list has been changed! Starting over...
[12/30/2008, 19:42:00] - BHO 1: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} (Ask Search Assistant BHO)
[12/30/2008, 19:42:00] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[12/30/2008, 19:42:00] - BHO 3: {3964D8D6-86D0-493A-B460-A805B5401114} (MSEvents Object)
[12/30/2008, 19:42:00] - ALERT: Found MSEvents Object!
[12/30/2008, 19:42:00] - BHO 4: {6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4} (MSEvents Object)
[12/30/2008, 19:42:00] - ALERT: Found MSEvents Object!
[12/30/2008, 19:42:00] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/30/2008, 19:42:00] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/30/2008, 19:42:00] - BHO 7: {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} (Ask Toolbar BHO)
[12/30/2008, 19:42:00] - Finished Searching Browser Helper Objects
[12/30/2008, 19:42:00] - *** Detected MSEvents Object
[12/30/2008, 19:42:00] - Trying to remove MSEvents Object...
[12/30/2008, 19:42:01] - Terminating Process: IEXPLORE.EXE
[12/30/2008, 19:42:02] - Terminating Process: RUNDLL32.EXE
[12/30/2008, 19:42:02] - Disabling Automatic Shell Restart
[12/30/2008, 19:42:02] - Terminating Process: EXPLORER.EXE
[12/30/2008, 19:42:02] - Suspending the NT Session Manager System Service
[12/30/2008, 19:42:02] - Terminating Windows NT Logon/Logoff Manager
[12/30/2008, 19:42:02] - Re-enabling Automatic Shell Restart
[12/30/2008, 19:42:02] - File to disable: C:\WINDOWS\system32\vtuvvvv.dll
[12/30/2008, 19:42:03] - Removing HKLM\...\Browser Helper Objects\{3964D8D6-86D0-493A-B460-A805B5401114}
[12/30/2008, 19:42:03] - Removing HKCR\CLSID\{3964D8D6-86D0-493A-B460-A805B5401114}
[12/30/2008, 19:42:03] - Adding Kill Bit for ActiveX for GUID: {3964D8D6-86D0-493A-B460-A805B5401114}
[12/30/2008, 19:42:03] - Deleting ATLEvents/MSEvents Registry entries
[12/30/2008, 19:42:03] - Removing HKLM\...\Winlogon\Notify\vtuvvvv
[12/30/2008, 19:42:03] - Searching for Browser Helper Objects:
[12/30/2008, 19:42:03] - BHO 1: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} (Ask Search Assistant BHO)
[12/30/2008, 19:42:03] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[12/30/2008, 19:42:03] - BHO 3: {6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4} (MSEvents Object)
[12/30/2008, 19:42:03] - ALERT: Found MSEvents Object!
[12/30/2008, 19:42:03] - BHO 4: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/30/2008, 19:42:03] - BHO 5: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/30/2008, 19:42:03] - BHO 6: {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} (Ask Toolbar BHO)
[12/30/2008, 19:42:03] - Finished Searching Browser Helper Objects
[12/30/2008, 19:42:03] - *** Detected MSEvents Object
[12/30/2008, 19:42:03] - Trying to remove MSEvents Object...
[12/30/2008, 19:42:04] - Terminating Process: IEXPLORE.EXE
[12/30/2008, 19:42:04] - Terminating Process: RUNDLL32.EXE
[12/30/2008, 19:42:04] - Disabling Automatic Shell Restart
[12/30/2008, 19:42:04] - Terminating Process: EXPLORER.EXE
[12/30/2008, 19:42:04] - Suspending the NT Session Manager System Service
[12/30/2008, 19:42:05] - Terminating Windows NT Logon/Logoff Manager
[12/30/2008, 19:42:05] - Re-enabling Automatic Shell Restart
[12/30/2008, 19:42:05] - File to disable: C:\WINDOWS\system32\pmnli.dll
[12/30/2008, 19:42:05] - Removing HKLM\...\Browser Helper Objects\{6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4}
[12/30/2008, 19:42:05] - Removing HKCR\CLSID\{6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4}
[12/30/2008, 19:42:05] - Adding Kill Bit for ActiveX for GUID: {6B68E904-D5EE-4D5F-AAF7-7298BF4E87C4}
[12/30/2008, 19:42:05] - Deleting ATLEvents/MSEvents Registry entries
[12/30/2008, 19:42:05] - Removing HKLM\...\Winlogon\Notify\pmnli
[12/30/2008, 19:42:05] - Searching for Browser Helper Objects:
[12/30/2008, 19:42:05] - BHO 1: {0579B4B1-0293-4d73-B02D-5EBB0BA0F0A2} (Ask Search Assistant BHO)
[12/30/2008, 19:42:05] - BHO 2: {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} (Adobe PDF Reader Link Helper)
[12/30/2008, 19:42:05] - BHO 3: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[12/30/2008, 19:42:05] - BHO 4: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[12/30/2008, 19:42:05] - BHO 5: {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} (Ask Toolbar BHO)
[12/30/2008, 19:42:05] - Finished Searching Browser Helper Objects
[12/30/2008, 19:42:05] - Finishing up...
[12/30/2008, 19:42:05] - A restart is needed.
[12/30/2008, 19:42:05] - Automatic Reboot on STOP Error is not set. User will have to manually restart.
[12/30/2008, 19:42:22] - Attempting to Restart via STOP error (Blue Screen!)