Step 1
Show hidden files through windows explorer
- Access Windows Explorer by clicking Start, point to All Programs, Accesories, and then click Windows Explorer. Or hold the windows key and press E
- On the Tools menu in Windows Explorer, click Folder Options.
- Click the View tab.
- Under Hidden files and folders, click Show hidden files and folders and Turn Hide protected operating system files off.
-------------------------------------------------------------------------------
Step 2
Download ATF Cleaner
Download
ATF Cleaner by Atribune to your desktop.
*Don't run till in safe mode
-----------------------------------------------------------------------------------
***Might want to copy and paste this into notepad and save it to desktop to have while in safe mode
Step 3
Please re-open HiJackThis and scan. Check the boxes next to all the entries listed below.
O4 - HKLM\..\Run: [Host Process] C:\Documents and Settings\Donovan Pratt\svchost.exe
O4 - HKLM\..\Run: [20fc799b] rundll32.exe "C:\WINDOWS\system32\vjbsenvn.dll",b
O4 - HKUS\S-1-5-21-725345543-606747145-839522115-1005\..\Run: [BM23cf4a07] Rundll32.exe "C:\DOCUME~1\DOUGAN~1\LOCALS~1\Temp\vnotafal.dll",s (User 'doug and noah')
Now
close all windows other than HiJackThis, then click Fix Checked. Close HiJackThis. Reboot into safe mode.
Restart your computer and as soon as it starts booting up again continuously tap F8. A menu should come up where you will be given the option to enter Safe Mode.
Using Windows Explorer (to get there right-click your Start button and go to "Explore"), please delete these
files (if present):
C:\Documents and Settings\Donovan Pratt\svchost.exe
C:\WINDOWS\system32\vjbsenvn.dll
Close windows explorer
--------------------------------------------------------------
Run ATF Cleaner
Double-click
ATF Cleaner.exe to open it.
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the
Empty Selected button.
Firefox or Opera:
Click
Firefox or
Opera at the top and choose:
Select All
Click the
Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click
NO at the prompt.
Click
Exit on the
Main menu to close the program.
------------------------------
After that, Reboot, and post a new HijackThis log here in a reply