We'll need to run KillVundo again to rmove the remaining Vundo file.
Please reboot your computer into Safe Mode.
Restart your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight Safe Mode then hit enter.
Once in safe mode open the
VundoFix folder and doubleclick on
KillVundo.bat
At the introductory screen, press <Enter> to proceed.
When asked to type in a filepath, please key this in:
- C:\WINDOWS\SYSTEM32\jkhhh.dll
Press
Enter to continue with the fix.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Next you will be asked to type in a second filepath.
At this point please type the following file path (make sure to enter it exactly as below!):
- C:\WINDOWS\SYSTEM32\hhhkj.* < - the asterix * is part of the filepath
Press
Enter to continue with the fix.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
The fix should then automatically launch HijackThis. (if it doesn't, you'll have to do it manually)
In HiJackThis, please place a check next to the following items and click
FIX CHECKED:
- O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\jkhhh.dll
O20 - Winlogon Notify: jkhhh - C:\WINDOWS\SYSTEM32\jkhhh.dll
After you have fixed these items, close Hijackthis and reboot your computer.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Once your machine reboots please continue with the instructions below.
Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "
Options..."
Move the arrow down to "
Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
Click
OK
Press the
CleanUp! button to start the program.
It may ask you to reboot at the end, click NO.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Then, direct a Panda scan on the C:\Windows\system32 directory
- Click Scan your PC
- Click Scan Now
- Begin the scan by selecting Other media
- Then browse to the C:\Windows\system32 directory
Copy the
results of the ActiveScan and paste them here along with a new
HiJackThis log and the
vundofix.txt file from the vundofix folder into this topic.
__________________
Question - what have you done for the community today?