Hello and Welcome
Please subscribe to this thread to get immediate notification of fixes as soon as they are posted.
Before we do anything else, please ensure that you have already patch your system against the recent WMF exploit. Please refer to my sig. No point we fix anything only for it to return tomorrow.
Before proceeding any further, please create a new directory - C:\PROGRAM FILES\HIJACKTHIS\
Re-locate your HijackThis files to the new directory
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download this tool and save it to your desktop. Then double click the tool and follow the instructions.
VirtumundoBeGone.exe
When its done, reboot and post the log that is created on your desktop called VBG.TXT in your next reply
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
With HiJackThis & place a check next to these items and select "Fix checked":
O2 - BHO: ATLDistrib Object - {3FE36807-69ED-45D1-B9BE-85C0E3F75B6A} - C:\WINDOWS\System32\awvtr.dll
O2 - BHO: (no name) - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - (no file)
O4 - HKLM\..\Run: [tndegc46] C:\WINDOWS\System32\tndegc46.exe
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O20 - Winlogon Notify: awvtr - C:\WINDOWS\System32\awvtr.dll
* * * * * * USING HIJACKTHIS' DELETE ON REBOOT * * * * * *
Start HiJackThis & go to Config>Misc.Tools> Delete a file on reboot...
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download and install CleanUp!
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
Press the CleanUp! button to start the program.
It may ask you to reboot at the end, click NO.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Then, perform an online scan with Internet Explorer with Panda ActiveScan
Copy the results of the ActiveScan and paste them here along with a new HiJackThis log and into this topic.
Please subscribe to this thread to get immediate notification of fixes as soon as they are posted.
Before we do anything else, please ensure that you have already patch your system against the recent WMF exploit. Please refer to my sig. No point we fix anything only for it to return tomorrow.
Before proceeding any further, please create a new directory - C:\PROGRAM FILES\HIJACKTHIS\
Re-locate your HijackThis files to the new directory
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download this tool and save it to your desktop. Then double click the tool and follow the instructions.
VirtumundoBeGone.exe
When its done, reboot and post the log that is created on your desktop called VBG.TXT in your next reply
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
With HiJackThis & place a check next to these items and select "Fix checked":
O2 - BHO: ATLDistrib Object - {3FE36807-69ED-45D1-B9BE-85C0E3F75B6A} - C:\WINDOWS\System32\awvtr.dll
O2 - BHO: (no name) - {6DD0BC06-4719-4BA3-BEBC-FBAE6A448152} - (no file)
O4 - HKLM\..\Run: [tndegc46] C:\WINDOWS\System32\tndegc46.exe
O16 - DPF: {0F04992B-E661-4DB9-B223-903AB628225D} (DoMoreRunExe.DoMoreRun) - file://C:\Program Files\Gateway\Do More\DoMoreRunExe.CAB
O16 - DPF: {739E8D90-2F4C-43AD-A1B8-66C356FCEA35} (RunExeActiveX.RunExe) - hcp://system/RunExeActiveX.CAB
O16 - DPF: {99CDFD87-F97A-42E1-9C13-D18220D90AD1} (StartFirstControl.CheckFirst) - hcp://system/StartFirstControl.CAB
O20 - Winlogon Notify: awvtr - C:\WINDOWS\System32\awvtr.dll
* * * * * * USING HIJACKTHIS' DELETE ON REBOOT * * * * * *
Start HiJackThis & go to Config>Misc.Tools> Delete a file on reboot...
- In the popup box that appears, copy/paste in:
- C:\WINDOWS\System32\tndegc46.exe
- Click the Open button.
- Click YES when prompted to restart your computer.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Download and install CleanUp!
Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "Options..."
Move the arrow down to "Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
Press the CleanUp! button to start the program.
It may ask you to reboot at the end, click NO.
* * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * * *
Then, perform an online scan with Internet Explorer with Panda ActiveScan
- Click Scan your PC & a 'pop up' window shall appear. *ensure that your pop up blocker doesn't block it
- Click Scan Now
- Enter your e-mail address & click Scan Now ...begins downloading 8 MB Panda's ActiveX controls
- Once the scan is complete, it will display if your system has been infected. It does not provide an option to clean/disinfect. We only require a report from it.
- Click on see report. Then click Save report
Copy the results of the ActiveScan and paste them here along with a new HiJackThis log and into this topic.