Welcome JupiterCries to Geeks to Go!
Please disable SpybotSD’s protection, as it may hinder the removal of the infection. You can enable it after you're clean.
Open Spybot and click on Mode and check Advanced Mode
Check yes to next window.
Click on Tools in bottom left hand corner.
Click on Resident icon.
Uncheck Teatimer box and/or Uncheck Resident.
Close Spybot.
***
Please print these instructions out for use in Safe Mode.
Please note: your Antivirus program may prompt you to a malicious script trying to run. Allow the entire script once.Please download
VundoFix.exe by Atribune© to your desktop.
- Double-click VundoFix.exe to extract the files
- This will create a VundoFix folder on your desktop.
- After the files are extracted, please reboot your computer into Safe Mode. You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Use your up arrow key to highlight Safe Mode then hit enter.
- Once in safe mode open the VundoFix folder and doubleclick on KillVundo.bat
- You will first be presented with a warning.
It should look like this
VundoFix V2.15 by Atri
By using VundoFix you agree that you are doing so at your own risk
Press enter to continue....
- At this point press enter one time.
- Next you will see:
Please Type in the filepath as instructed by the forum staff
and then press enter:
- At this point please type the following file path (make sure to enter it exactly as below!):
- C:\WINDOWS\system32\ssqpp.dll
- Press Enter to continue with the fix.
- Next you will see:
Please type in the second filepath as instructed by the forum
staff then press enter:
- At this point please type the following file path (make sure to enter it exactly as below!):C:\WINDOWS\system32\ppqss.*
- Press Enter to continue with the fix.
- The fix will run then HijackThis will open, if it does not open automatically please open it manually.
- In HiJackThis, please place a check next to the following items and click FIX CHECKED:
O2 - BHO: MSEvents Object - {FC148228-87E1-4D00-AC06-58DCAA52A4D1} - C:\WINDOWS\system32\ssqpp.dll
O20 - Winlogon Notify: ssqpp - C:\WINDOWS\system32\ssqpp.dll - After you have fixed these items, close Hijackthis.
- Press enter to exit the program then manually reboot your computer.
- Once your machine reboots please continue with the instructions below.
Download and install
CleanUp!Open
Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:
Click "
Options..."
Move the arrow down to "
Custom CleanUp!"
Put a check next to the following (Make sure nothing else is checked!):
- Empty Recycle Bins
- Delete Cookies
- Delete Prefetch files
- Cleanup! All Users
Click
OKPress the
CleanUp! button to start the program.
It may ask you to reboot at the end, click NO.
Run the
Free use Panda Active ScanCopy the
results of the ActiveScan and paste them here along with a new
HijackThis log and the
vundofix.txt file from the vundofix folder into this topic.