Save it to your desktop.

Now we need to complete this whole process by getting rid of your older/infected restore points; and creating a new cleaner one.

I had been paying for McAfee and after reading up on avast and comodo, decided to give them a try thanks again, Matt Feb 17, 2010 #14 (You must log In the command window, type the following, pressing Enter after typing each line:cd\cd downloadschktrust -i FixVundo.exe You should see one of the following messages, depending on your operating system:Windows XP SP2:The

This tool uses JavaScript and much of it will not work correctly without it enabled. IF Malwarebytes Chameleon will not open, double-click on the other renamed files until you find one will work, which will be indicated by a black DOS/command prompt window.

I'm wondering if the virus did something to block its use, because norton won't open either. When the scan will be completed,you will be presented with a screen reporting which malicious files has Emsisoft detected on your computer, and you'll need to click on Quarantine selected objects to

STEP 4: Remove Trojan Vundo rootkit with HitmanPro you can download HitmanPro from the below link,then double click on it to start this program. I'd like to check the 2 logs first.

Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one. What is this: C:\Documents and Settings\User\My Documents\syzm.rtf ?

Download and save the Chktrust.exe file to the same folder in which you saved the removal tool.Note: Most of the following steps are done at a command prompt. Security products may detect this trojan, with the following name: Trojan:Win32/Vundo.K (Microsoft),Trojan:Win32/Vundo.gen!R (Microsoft), TR/Drop.Vundo.J.70 (Avira), Gen:Variant.Vundo.4 (BitDefender),TR/Vundo.NV.2 (Avira), Win-Trojan/Vundo.63488.M (AhnLab),Trojan.Vundo.B (Symantec) , W32/Vundo.dam1 (Norman), Win32/Vundo!generic (CA), Trojan.Vundo.EWZ (BitDefender),Trojan.Vundo.B (Symantec) , Vundo.gen165

Mozilla's Firefox browser is fantastic; it is much more secure than Internet Explorer, immune to almost all known browser hijackers, and also has the best built-in popup blocker (as an added Then save the Chktrust.exe file to the root of C as well.(Step 3 to assume that both the removal tool and Chktrust.exe are in the root of the C drive.)

You can do this by restarting your computer and continually tapping the F8 key until a menu appears. Viruses often take advantages of bugs or exploits in the code of these programs to propagate to new machines, and while the companies that make the programs are usually quick to

Kill the file ACTIVETOOLBAND.DLL and remove ACTIVETOOLBAND.DLL from Windows startup.

Keep your Anti-Virus and Firewall updated.

Then, run a regular scan of the system with proper exclusions: "C:\Documents and Settings\user1\Desktop\FixVundo.exe" /NOFILESCAN /LOG=c:\FixVundo.txt Note: You can give the log file any name and save it to any location.

Close all the running programs.

