After you complete the above, REBOOT and proceed with the rest of this fix... I ran Vundofix and it found 4 files 1 of which it could not remove so it restarted found another file which it removed but still could not get rid of indicates an unprintable character so it will not look normal. TimW, May 18, 2007 #8 giggityjeep Private E-2 I noticed the bump sticky after I posted again sorry, my GF is nagging me to get this going, she needs it for have a peek here

Finally, I would like you to flush your System Restore points. HJT Log in or Sign up MajorGeeks.Com Support Forums Home Forums > ----------= PC, Desktop and Laptop Support =------ > Malware Help - MG (A Specialist Will Reply) > I also appeared to have several trojans. I eventually managed to use system restore to fix it.

One or other of these problems kept bringing up spam webpages and fake security risk pop-ups from my start bar, which was annoying so I set about sorting it out. If I have any problems in the future I will definately come here first! TimW, May 17, 2007 #2 giggityjeep Private E-2 AWSOME will do tonight, and post my results in this Thread...god ya know people that do this crap should be thrown off a Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Doodlez, Nov 5, 2006.

Now run Pocket Killbox by doubleclicking on killbox.exe Choose Tools > Delete Temp Files and click Delete Selected Temp Files. Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support Make sure you check version numbers and get all updates. still getting pop ups soon as I go on internet, and I still have 'windows safety alert' in my control panel...that I cant get rid of...lost here guys....direct me... No, create an account now

NOTE: Pocket Killbox will only list the added files it is able to find on the system. By continuing to use this site, you are agreeing to our use of cookies. giggityjeep, May 18, 2007 #9 TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member Is this something you installed: MSSoap? Click the Red X for each entry, but DO NOT Allow your machine to be rebooted until the last item has been entered: ** Note: For any of the .dll files,

If so please attach a fresh one from normal mode. Please select the “Delete on Reboot” Option. Then, follow the instructions at the bottom of the linked page to Re-enable the Restore Utility which will create a fresh restore point. I have attached the VundoFix log and a new HijackThis log.

I followed all the steps on the removal tutorial thread (clearing quarantined items, running CCleaner, Spybot S&D, Windows Defender, repeating it all in safe mode, running BitDefender, PandaActiveScan and getrunkey, shownew http://forums.majorgeeks.com/index.php?threads/malware-spiralling-out-of-control.106688/ Now attach the below new logs and tell me how the above steps went. 1. Thanks again for your great help. Please follow the instructions in the below: Disable and Re-enable System Restore Turn OFF System Restore to flush any bad Restore Points.

After discovering this new problem I ran Spybot S&D and Ad-AwareSE and managed to remove about 15 problems. navigate here However, all was going well until I returned to my computer after the PandaActiveScan (in safe mode) to find about 4 pop-ups from "virus-scan" programmes and several flashing icons and balloons Let me know of any problems you may have encountered with the above instructions and also let me know how things are running now and attach a fresh HJT log. Run HijackThis and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now: O2 - BHO: (no

Very Important: Make sure you tell us the results from running the tutorial...was anything found? Doodlez x Doodlez, Nov 9, 2006 #8 bjgarrick MajorGeeks Admin - Malware Expert I hate to hear your formatting however it's up to you. By continuing to use this site, you are agreeing to our use of cookies. Check This Out I was using Panda anti virus and Windows defender....I have tried Ad Aware, and rerun Panda, the crappy thing is Panda dont quarantine anything just renames it, and it wont disinfect

If Killbox does not reboot just reboot your PC yourself. Next, run CCleaner to clean up cookies and temp files. GetRunKey 2.

Download this file - Combofix.exe 2.

When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too: CounterSpy AVG Antispyware log Then after it deletes the files click the Exit (Save Settings) button. Also there are steps included for installing, running, and posting HijackThis logs as attachments. Thanks, Doodlez Attached Files: bdscan.txt File size: 20.3 KB Views: 1 newfiles.txt File size: 30.1 KB Views: 1 runkeys.txt File size: 15.4 KB Views: 1 Doodlez, Nov 5, 2006 #1

Continue by downloading a tool we will need - Pocket KillBox Save it to its own folder somewhere that you will be able to locate it later. I have run out of ideas what to do and am desperate! (I have attached the BitDefender, getrunkey and shownew logs and will attach the hijackthis log on a post below.) C:\WINDOWS\nvp2pmon.exe C:\WINDOWS\system32\nvp2pmon.exe C:\WINDOWS\system32\ofppxtbv.dll C:\WINDOWS\system32\geedd.dll C:\WINDOWS\system32\drvxoj.dll C:\WINDOWS\system32\lvsaksm.dllClick to expand... this contact form Since then my virus problems seem to be spiralling out of control!

When finished, it will produce a log for you. etc. C:\WINDOWS\??mantec C:\Program Files\LAUNCH~1 C:\Documents and Settings\Jane\Application Data\CROSOF~1.NET Now scan with HijackThis and check the boxes for the following entries: ( Make sure ALL browser windows are closed when you click FIX Once you complete the above attach the log from the scan along with a fresh HJT log.

Select: * Delete on Reboot * then Click on the All Files button. * Please copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL Locate PocketKillbox (Procede with this step even if they do not show in blue) Next, you will be entering items into Pocket KillBox. If you get an error message about Pending Operations, just reboot your computer manually. Click Yes at the Delete on Reboot prompt.

Just so you know the ? I am now reluctant to try any more fixes that I don't fully understand myself and, as my computer is due a re-format anyway, am just gonna get rid of the Use analyse.exe for the new name. bjgarrick, Nov 5, 2006 #3 Doodlez Private E-2 Thanks for your advice.

thanks giggityjeep, May 17, 2007 #1 TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member Welcome to Majorgeeks! giggityjeep Private E-2 New here today.. Good Luck! Were you unable to complete any of the scans?...Were you unable to download any of the tools?...Did you do the on-line scans as suggested?

Please use add/remove to uninstall: J2SE Runtime Environment 5.0 Update 3 Windows Safety Alert Use windows explorer to find and delete: C:\Program Files\Video ActiveX Access\ Reboot and install: Java Runtime 6 Malware spiralling out of control! giggityjeep, May 18, 2007 #7 TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member Please read this: http://forums.majorgeeks.com/showthread.php?t=104916 I will be working up a fix and will post the steps soon. Learn More.

After you complete the above reboot once more and then scan with HijackThis and attach the new log.