Once either of the three safe-boot methods are selected (ie safe mode, safe mode with networking or safe mode with command prompt), I either get a reboot that loads me normally

Help! Ask a question and give support. Hi, I discovered that I have the Vundo Virus (Vundo!.grb). I've attached the log here.

The log from 3/16 reflected 64 infected files that were removed.

Note: Combofix will run without the Recovery Console installed. The connection is automatically restored before CF completes its run.

When completed, it will prompt that it will reboot your computer, click OK. Please download ATF Cleaner by Atribune. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal

Please don't attach the scans / logs, use "copy/paste". this content Pinging google.com [] with 32 bytes of data: Reply from bytes=32 time=11ms TTL=58 Reply from bytes=32 time=8ms TTL=58 Ping statistics for Packets: Sent = 2, The virus that continuously shows up in my virus scan logs is one called the "Vundo!grb". When done, DDS.txt will open.

I learned there that "You must disable the System Restore Utility to remove the infected files from the C:\_Restore folder, so I did that. This is what's happening-- I've been getting pop-ups in my browser (Firefox v. 3.0.6).

It is a virus, which gets attached to some files in your computer and programs that you download from internet.

Machine seems to be running normally--no problems. I would advise backing up all of your data and then re installing.

Further, because of the fact that this program would load with windows on startup, my pc would constantly or start to function erradically. Most of these were to mycoolsearch.com. Finally, delete the following folders if they still exist: C:\Program Files\ViewManager\ C:\Program Files\Viewpoint\

Thank you very much for taking the time to read my post. -meloman c:\windows\system32\cxcahxsg.dll c:\windows\system32\fhhrur.dll c:\windows\system32\llyvkp.dll c:\windows\system32\wepsufok.dll

C:\WINDOWS\system32\ilropnaa.dll (Trojan.Vundo) -> Quarantined and deleted successfully. Unfortunately, I was only able to complete the process through step 3. After nearly an hour elapsed, causing 3 reboots and multiple scans, ComboFix finally generated a log. Prior to this, a new tab would open in the existing window.

When it is complete, it will open a text file in notepad called AWF.txt which will automatically be saved to your desktop or to the same location as FindAWF.exe.

