View Single Post
Old 12-07-2007, 06:14 PM   #8 (permalink)
Go The Power
Moderator, Microsoft Support
 
Go The Power's Avatar
 
Join Date: Mar 2007
Location: South Australia
Posts: 11,006
OS: Windows XP Home SP2


Blog Entries: 1
Send a message via MSN to Go The Power Send a message via Skype™ to Go The Power
Re: Trojan.vundo, Constant Popups and slowed system.

Please read these instructions very carefully, and follow them in the exact order I have listed. If you don’t understand any part of the fix please ask before proceeding.

You may want to print out these instructions, or copy them into Notepad.

Please note: Just because you have lack of symptoms it doesn’t mean the problem is gone. Please stay with me until I declare your log’s clean. Thank you.

=====================

Download

Click Here to download ATF Cleaner by Atribune. Save it to your Desktop.

=====================

1. Close any open browsers.

2. Open notepad and copy/paste the text in the quotebox below into it:

Quote:
File::
C:\WINDOWS\system32\nqtwa.ini2

Registry::
[-HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{35A2EE48-9FA3-4C88-A66C-AB897F224865}]
Save this as CFScript.txt, in the same location as ComboFix.exe




Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at "C:\ComboFix.txt"

**Please Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall**

=====================

Clean TEMP files

Go to your desktop and double click on ATF-Cleaner.exe.

Main

Under Main. Click Select All, then click Empty

----------------------------

If you use Firefox, click Firefox on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved Passwords click No on the prompt.

----------------------------

If you use Opera, click Opera on the menu bar

Click on Select All, then click Empty
Note: If you want to keep your saved Passwords click No on the prompt.

=====================

Please produce a fresh Hijackthis log

=====================

Required Logs

In your next reply please include:
  • Combofix.txt
  • Hijackthis.log
Also how is your system behaving now?
__________________


Go The Power is offline