Home / Software / Computer viruses and spyware / Please Help Me! i Cant Get Rid of A Virus!
0 Members and 3 Guests are viewing this topic. « previous next »
Pages: 1 [2]  All - (Bottom) Print
Author Topic: Please Help Me! i Cant Get Rid of A Virus!  (Read 4129 times)
xavier20
Topic Starter
Rookie



Posts: 13


« Reply #15 on: November 26, 2007, 01:56:17 AM »

ok done

[saving disk space - old attachment deleted by admin]
IP logged
xavier20
Topic Starter
Rookie



Posts: 13


« Reply #16 on: November 26, 2007, 02:10:09 AM »

so is it all good now?
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #17 on: November 26, 2007, 02:16:20 AM »

Almost there.

Delete these files/folders, as follows:

* Open notepad and copy/paste the text in the quote box below into it (all except the word QUOTE):

Quote
Folder::
C:\VundoFix Backups

File::
C:\WINDOWS\system32\fwgogyjf.ini

* Save this as CFScript on the desktop.
* Then drag the CFScript (hold the left mouse button while dragging the file) and drop it (release the left mouse button) into ComboFix.exe as you see in the screenshot below. Important: Perform this instruction carefully!


* ComboFix will begin to execute, just follow the prompts. After reboot (in case it asks to reboot), it shall produce a log for you. Post that log (Combofix.txt) in your next reply.

Note: Do not mouseclick combofix's window while it is running. That may cause your system to hang.

Next post
New combofix log
Another new Hijackthis log
IP logged

xavier20
Topic Starter
Rookie



Posts: 13


« Reply #18 on: November 26, 2007, 02:28:55 AM »

k

[saving disk space - old attachment deleted by admin]
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #19 on: November 26, 2007, 02:50:27 AM »

Open HijackThis and select "Do a system scan only"

Place a check mark next to
O4 - HKLM\..\Run: [10bfcfd3] "rundll32.exe" "C:\WINDOWS\system32\fjygogwf.dll",b

Click "Fix checked"

=====

Enable Viewing Of Hidden System Files & Folders

1. Right Click Start.
2. Select Control Panel.
3. Select the Tools menu and click Folder Options.
4. Select the View Tab.
5. Under the Hidden files and folders heading select Show hidden files and folders.
6. Uncheck the Hide extensions for known file types option.
7. Uncheck the Hide protected operating system files (recommended) option.
8. Click Apply.
9. Click OK.

Now go to C:\WINDOWS\system32\fjygogwf.dll and delete the file/folder (if found)

=====

Go to Start > Run and copy and paste next command in the field:

ComboFix /u



Make sure there's a space between Combofix and /
Then hit Enter.

This will uninstall Combofix, delete its related folders and files, reset your clock settings, hide file extensions, hide the system/hidden files and resets System Restore again.

=====

Delete any logs and programs like smitfraud and vundofix from the desktop.

=====

Run HijackThis and look for the C:\WINDOWS\system32\fjygogwf.dll entry. If it is still there let us know.

Other than that the logs are clean.

To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?

Let us know if anything else comes up.



IP logged

xavier20
Topic Starter
Rookie



Posts: 13


« Reply #20 on: November 26, 2007, 03:00:35 AM »

Nah cant find it. all looks good. the computers working fine. Thankyou so much for helping me
IP logged
evilfantasy
Malware Removal Specialist
Moderator
Genius



Thanked: 462
Posts: 11,769

Experience: Beginner
OS: Windows 7


Calm like a bomb

evilfantasy's blog
« Reply #21 on: November 26, 2007, 03:05:53 AM »

Sounds good!

Safe surfing.....
IP logged

Pages: 1 [2]  All - (Top) Print 
Home / Software / Computer viruses and spyware / Please Help Me! i Cant Get Rid of A Virus! « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.112 seconds with 20 queries.