This is an older version of Vundo that VundoFix will not remove. Not difficult, but time consuming. I contacted the author of VundoFix and havet he fix for this one.
Print these instructions and read over them before you begin. If you have any questions, ask before you start.
Ok, here we go....
Close all open windows and exit any open programs.
Open a new, blank, Notepad document. Copy the following file list to it, and then save it to your Desktop for easy location. The choice of file name is up to you.
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\varba.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\siicca.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\spitna.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gepjpa.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\cpkab.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\cvssab.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\tuntac.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\codrc.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gmibd.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gmicod.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\nurcod.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\padvd.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\nibalue.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\pctalue.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\sapxe.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\nibpxe.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\tenixaf.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\systnof.dat
C:\DOCUME~1\DANIEL~1\LOCALS~1\Temp\nutnof.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\smwptf.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\agvsii.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\xafgmi.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\golgmi.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\vaavaj.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\kabniam.da
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gercm.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\vrs3pm.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\tensm.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\syssm.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gerten.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\dmctun.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\bewcbdo.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\codnur.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\cvsmnur.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\pxes.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\avajvrs.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\gerrvs.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\ksatrvs.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\bkipat.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\smwksat.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\pipct.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\cfmpct.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\yeknu.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\ksidlru.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\dvdlru.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\pctlru.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\cmlitu.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\sassv.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\tenevaw.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\tacw.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\drahniw.dat
C:\DOCUME~1\MICHAE~1\LOCALS~1\Temp\avajlmx.dat
Once you have that done, then download the following beta version of KillBox to your Desktop:
http://www.killbox.net/downloads/beta/KillBox_b862.exe
Double Click on KillBox to start the program.
Select 'Run as System Task' from the file menu
Wait for the program to re-open
Open the list of files you created earlier.
Click 'Processes' Killbox menu item
A window to the right will slide open
Put a check mark beside the following processes, if present:
smss.exe
winlogon.exe
rundll32.exe
explorer.exe
iexplore.exe
Click the 'End Task' button
Next copy each filename from the file list, one a time. Paste it into Killbox and click the 'Delete' button (red circle with white x).
Once you have all the files entered, select 'Options', 'Shutdown', 'Forced Reboot' from Killbox.
This will reboot the system and delete the files.
Once you have restarted, do the following...
Launch Notepad.
Copy/paste the text in the box below into a new text file.
Save it as
fixme.reg on your Desktop
REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify]
"abrav"=-
"abrav"=-
"acciis"=-
"antips"=-
"apjpeg"=-
"bakpc"=-
"bassvc"=-
"catnut"=-
"crdoc"=-
"dbimg"=-
"docimg"=-
"docrun"=-
"dvdap"=-
"eulabin"=-
"eulatcp"=-
"expas"=-
"expbin"=-
"faxinet"=-
"fontsys"=-
"fontun"=-
"ftpwms"=-
"iisvga"=-
"imgfax"=-
"imglog"=-
"javaav"=-
"mainbak"=-
"mcreg"=-
"mp3srv"=-
"msnet"=-
"mssys"=-
"netreg"=-
"nutcmd"=-
"odbcweb"=-
"rundoc"=-
"runmsvc"=-
"sexp"=-
"srvjava"=-
"svrreg"=-
"svrtask"=-
"tapikb"=-
"taskwms"=-
"tcpip"=-
"tcpmfc"=-
"unkey"=-
"urldisk"=-
"urldvd"=-
"urltcp"=-
"utilmc"=-
"vssas"=-
"wavenet"=-
"wcat"=-
"winhard"=-
"xmljava"=-
Locate
fixme.reg on your Desktop and double-click on it.
You will receive a prompt similar to: "Do you wish to merge the information into the registry?".
Answer 'Yes' and wait for a message to appear similar to "Merged Successfully".
FInally, run HiJackThis again and post a new log in this thread.