3 Apprentice

 • 

8.8K Posts

September 6th, 2005 20:00

Let's get started.

Please download VundoFix.zip to your desktop.
  • Double-click VundoFix.zip and extract it to your C:\ directory.
  • Copy the instructions below and paste them into Notepad for reference.
    • All other windows need to be closed while doing this fix!
  • Navigate to the new folder C:\VundoFix
  • Double click on KillVundo.bat
    • When it starts running it will tell you that you need an active internet connection then ask you to press any key once you do.
  • Please press any key to continue.
  • Wait for HiJackThis to open.
  • When HiJackThis opens, click Do a system scan only. Place a check next to the following items, if found:


    • O2 - BHO: (no name) - {549B5CA7-4A86-11D7-A4DF-000874180BB3} - (no file)
      O2 - BHO: (no name) - {5CA3D70E-1895-11CF-8E15-001234567890} - (no file)
      O2 - BHO: (no name) - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - (no file)
      O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\repair\cmd.dll
      O2 - BHO: (no name) - {FDD3B846-8D59-4ffb-8758-209B6AD74ACC} - (no file)

      O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll

      O4 - Startup: AppRocket.lnk.disabled
      O4 - Startup: Rainlendar.lnk.disabled
      O4 - Startup: Stardock ObjectDock.lnk.disabled

      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
      O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
      ...(Unless you've set these with a anti-spyware program like SpyBot's Immunize feature, have HiJackThis fix this.)

      O20 - Winlogon Notify: cmd - C:\WINDOWS\repair\cmd.dll


      Once they all have a check next to them, click the FIX CHECKED button, then close HiJackThis.You will once again be prompted to press any key. Upon doing so this time you will receive a "Blue Screen Of Death". Don't worry,this is normal!
      Let the computer reboot. If it doesn't boot straight to windows,
      manually turn the computer off and then back on.

      After you boot up Locate and delete the following item(s), if present. Make sure your able to view system and hidden files/ folders:

      folders...
      C:\WINDOWS\repair
      C:\PROGRA~1\FlashGet

      Note that some of these file(s) may or may not be present. If present, and cannot be deleted because they're ' in use', try deleting them from " Safe Mode".


    Reboot and post back a new log, and let me know how everything goes.
    Steve
    -

    Once the computer is rebooted post a new HiJackThis log as well as the contents of vundofix.txt which can be found in this folder: C:\VundoFix
No Events found!

Top