The virus/trojan hooks into the Winlogon.exe process. In order to remove it, the Virtumundo tools have to kill that process which is responsible for handling logon and logoffs (and shutdowns). When the tool is done, it reactivates the NT Session Manager which notices WINLOGON is missing and it makes a STOP error.
The tool makes a registry change to allow the system to auto restart after this STOP error.
I could do more to kill just about every process on the system, but then users would have no way of shutting down the computer besides manually doing it.
secured2k
2 Intern
•
247 Posts
0
October 20th, 2005 02:00