Welcome to GTG. Please print out or copy this page to Notepad. Make sure to work through the fixes in the exact order it is mentioned below. If there's anything that you don't understand, ask your question(s) before proceeding with the fixes. You should 'not' have any open browsers when you are following the procedures below. Please download VundoFix.exe at http://www.atribune.org/downloads/VundoFix.exe to your desktop. * Double-click VundoFix.exe to extract the files. * After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key (or F5 in some machines) until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter. * Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat * Please type the following file path (make sure to enter it exactly as below!): C:\WINDOWS\system32\awtqo.dll * Press Enter, then press the F6 key, then press Enter one more time to continue with the fix. * When asked for a second path, enter -> C:\WINDOWS\system32\oqtwa.* * Press Enter, then press the F6 key, then press Enter one more time to continue with the fix. * The fix will run then HijackThis will open. * In HijackThis, please place a check next to the following items and click FIX CHECKED: O2 - BHO: MSEvents Object - {827DC836-DD9F-4A68-A602-5812EB50A834} - C:\WINDOWS\system32\awtqo.dll O20 - Winlogon Notify: awtqo - C:\WINDOWS\system32\awtqo.dll * After you have fixed these items, close Hijackthis and Press any key to Force a reboot of your computer. * Pressing any key will cause a 'Blue Screen of Death' this is normal, do not worry! * Once your machine reboots please continue with the instructions below. Download and install CleanUp! http://www.greyknight17.com/spy/CleanUp.exe Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu). Set the program up as follows: Click 'Options...' Move the arrow down to 'Custom CleanUp!' Put a check next to the following (Make sure nothing else is checked!): * Empty Recycle Bins * Delete Cookies * Delete Prefetch files * Cleanup! All Users Click OK. Press the CleanUp! button to start the program. It may ask you to reboot at the end, click NO. Then, please run an online virus scan at ActiveScan http://www.pandasoftware.com/products/activescan.htm Copy the results of the ActiveScan and paste them here along with a new HijackThis log and the vundofix.txt file from the vundofix folder into this topic.