![]() |
|
#11
| |||
| |||
| Your Java is out of date. Older versions have vulnerabilities that malicious sites can use to infect your system. First install the new Sun Java Runtime Environment Be sure to close all browser windows before beginning the install. Remove the old version(s) Download JavaRa
---------- Open HijackThis and select Do a system scan only. Place a check mark next to the following entries: (if there) O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll (file missing) O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) Important: Close all windows except for HijackThis and then click Fix checked. Exit HijackThis. ---------- See if you can scan this file please. Suspicious files to scan Please go to VirSCAN.org FREE on-line scan service (If more than one file needs scanned they must be done separately and logs posted for each one) 1. Copy and paste the following file path into the Suspicious files to scan box on the top of the page. Code: C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL Start.exe 3. Press Ctrl+V on the keyboard (both at the same time) to paste the file path into the window. 4. Click on the Upload button. This will perform a scan across multiple different virus scanning engines. Your file will possibly be entered into a queue which normally takes less than a minute to clear. Important: Wait for all of the scanning engines to complete. 5. Once the Scan is completed scroll down and click on the Copy to Clipboard button. This will copy the link of the report into the Clipboard. 6. Paste the contents of the Clipboard in your next reply. |
|
#12
| |||
| |||
| Done all of that except the last bit.. I've tried 5-6 times pasting that into the box, then click upload... A little box appears for about 3-4secs as if it's scanning or something then another box pops up saying 'Error: Can't find upload file!' |
|
#13
| |||
| |||
| |
|
#14
| |||
| |||
| Nope, just came up with 0 bytes recieved |
|
#15
| |||
| |||
| Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Go to Start > Run and type notepad.exe then click OK Copy and paste the below into Notepad and save as fixme.reg to Your Desktop Code: REGEDIT4
[-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{069b2f09-8c7d-11dc-871c-0013205c16a9}]
Make sure that you tell me if you receive a success message about adding the above to the registry. If you do not get a success message, it did not work. Delete the fixme.reg from the Desktop. ---------- Download CCleaner Slim and save it to your Desktop.- Alternate download link
Run the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
![]() Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%. |
|
#16
| |||
| |||
| -------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER 7 REPORT Friday, November 7, 2008 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600) Kaspersky Online Scanner 7 version: 7.0.25.0 Program database last update: Thursday, November 06, 2008 22:11:34 Records in database: 1372920 -------------------------------------------------------------------------------- Scan settings: Scan using the following database: extended Scan archives: yes Scan mail databases: yes Scan area - My Computer: C:\ D:\ Scan statistics: Files scanned: 58405 Threat name: 2 Infected objects: 2 Suspicious objects: 0 Duration of the scan: 02:04:01 File name / Threat name / Threats count C:\Stuff from Previous Install\Adam\Desktop\ComboFix.exe Infected: Trojan.BAT.Agent.ak 1 C:\Stuff from Previous Install\Adam\Desktop\ComboFix.exe Infected: Trojan.WinREG.Qoologic 1 The selected area was scanned. |
|
#17
| |||
| |||
| Time to do some cleanup and secure the work you have done.
Download OTCleanIt.exe and save it to your Desktop.
Set a New Restore Point to prevent possible reinfection from an old one Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
Windows XP System Restore Guide or Windows Vista System Restore Guide ---------- Use the Secunia Software Inspector to check for out of date software. Out of date software has security vulnerabilities that malware can exploit.
Go to Microsoft Windows Update and get all critical updates. ---------- Make sure all of your security programs are up to date and run scans with them regularly. Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0. To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I would suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for these ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself safe On The Web for tips and free tools to keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth. |
|
#18
| |||
| |||
| First off - thanks a a lot for the help Evil.. Secondly, just tried the 1st two bits you've asked just then - neither will work. First one says Combofix cannot be found Second one says Page Cannot be Displayed? |
|
#19
| |||
| |||
| Oops! Don't worry about Combofix and I fixed the second part of the instructions. The OTCleanIt link should work fine. |