My problem started about 3 weeks ago when I noticed my google searches kept being redidected & I keep getting all these annoying pop-up ads. To do this, click Start>Run, type REGEDIT in the text box provided, then press Enter In the left panel of the Registry Editor window, double-click the following: HKEY_LOCAL_MACHINE>SYSTEM>CurrentControlSet> Services

After I click next nothing happens. & I keep getting this annoying yellow pop up box that says "Your browser is under the threat of infection. Should I run the same script? For best results, recheck each rootrepeal scan results in safe mode back to back (delete files in safe mode, reboot to safe mode again to rescan).Also, about the Boot CD crash Here are the logs since using Combo Fix...

  1. MBAM cant get rid of it.
  2. As Daniel observes above, help is unusual in that it doesn't require to, although it also doesn't forbid it.
  5. The reason is that due to your problem  I had Catchme hopefully successfully remove the files, but we haven't touched the registry entries that include a disallowed list.
  6. move it results#89593imspsIntermediate Posts : 62OS : vistaRubies : 27608Likes : 0 imsps on 12th September 2009, 1:46 pmFolder move failed.
  7. In the "Input script here:" copy and paste the script between the lines Drivers to disable: MSIVXserv.sys Drivers to delete: MSIVXserv.sys Files to delete: C:\Autorun.inf D:\Autorun.inf C:\Windows\System32\drivers\MSIVXhxlsrhnhnoclieptjydpumfyypkcuamt.sys  C:\WINDOWS\system32\MSIVXaowehrinrdmtohwvqltifkjstoedkkqq.dll C:\WINDOWS\system32\MSIVXaplpaqettwnjltmaaxnmjfpsqlpamuxm.dll   C:\WINDOWS\System32\MSIVXcount Registry
  8. File, Invisible to Win32: C:\WINDOWS\System32\MSIVXcount File, Invisible to Win32: C:\WINDOWS\System32\MSIVXkfjefjjurxdutmyxnveavvljmarkpqmx.dll File, Invisible to Win32: C:\WINDOWS\System32\MSIVXopneldfwbkqobowtjpgeduimiobybgtl.dll File, Invisible to Win32: C:\WINDOWS\System32\drivers\MSIVXmfasbqwbmebrvfvioxdxfnvocoqaxpdu.sys File, Invisible to Win32: C:\Users\Michael\AppData\Local\Temp\_tc\MSIVXcount File, Invisible to Win32: C:\Users\Michael\AppData\Local\Temp\_tc\MSIVXkfjefjjurxdutmyxnveavvljmarkpqmx.dll Folder,

Before you scanned with MBAM, did you UPDATE the program?If you did not, pls. post the log, so we can see what it finds.

Heres what happened... Posted: 12-Jul-2009 | 2:36PM • Permalink Im not sure about the BitDefender Removal Tool but Im guessing not if there is still traces of it in the system. Be careful where you get it from.

Posted: 13-Jul-2009 | 9:40AM • Permalink Ok, thanks. please tell me what I need to do, as my computer is my job its super important, I get this fixed asap. When I try to wipe it, it says it's wiped, but it doesn't disappear from the list, and it's still there when I reboot and run the scan again.

Typically it is msn.com or whatever you have chosen as default. In the Named input box, type: MSIVXcount In the Look In drop-down list, select My Computer, then press Enter. This tool uses JavaScript and much of it will not work correctly without it enabled.

RE: Need help with NTOSKRNL-HOOK removal PortlandGirl Jun 25, 2009 12:48 AM (in response to secured2k) It appears that my problems are still not fixed. Thanks.

Use your forum Name on Pastebay please make sure the whole gmer log get posted, Also, use GMER only to do the log its way too powerful that you can damage Posted: 11-Jul-2009 | 11:20AM • Permalink Hi Faz: Please follow the instructions for providing logs, as given. Check all boxes. I seem to have caught a few nasty things that Norton isnt picking up.

I could do another RootRepeal scan to see if the service file still shows up.

This applies only to the originator of this thread.Other members who need assistance please start your own topic in a new thread.

If you leave it in, your sentence will still be correct, though. In that context, the first sentence means, essentially, "please help me develop an understanding of this (in the future)". Posted: 13-Jul-2009 | 8:58AM • Permalink Hi, here is the Malwarebytes log from the check Ive just done. Is there a way I can shut it down through task manager or can I run that script without disabling it?

Posted: 11-Jul-2009 | 2:16PM • Permalink I am looking up the error code, I may have to change programs and script types

Ive used regedit before but only because I had some other viruses going by the names a.exe, b.exe, c.exe and msav.exe (I think). What do I do? Please check this Knowledge Base page for more information.

Step5:Scan your computer with your Trend Micro product to delete files detected as TROJ_ALUREON.AME $$NOTES=If the detected files have already been Posted: 11-Jul-2009 | 3:16PM • Permalink Press the script tab Use this script Files to kill: C:\WINDOWS\system32\drivers\MSIVXhxlsrhnhnoclieptjydpumfyypkcuamt.sys C:\WINDOWS\system32\MSIVXaowehrinrdmtohwvqltifkjstoedkkqq.dll C:\WINDOWS\system32\MSIVXaplpaqettwnjltmaaxnmjfpsqlpamuxm.dll   C:\WINDOWS\System32\MSIVXcount   Then "Run" and "Restart" like in the screenshot above

If we have ever helped you in the past, please consider helping us. So if that comes up all clear, I just need to get Sym AV back up and running and a fresh reboot. Click "Execute" You will be asked to restart the PC click "Yes", when the PC restarts the load screen will takes slightly longer, then when it looks as though windows is Re: msivxcount - can't remove it#80124BelahzurSite Admin Posts : 34942OS : 7 Home Premium x64Rubies : 245603Likes : 10 Belahzur on 4th August 2009, 7:02 pmDid Spybot interfere?

After the restart, it creates a log file that should open with the results of Avengers actions.