siliconman01
Global Moderator
    
 Trojans! Chew 'em Up, Spit 'em Out...
Gender: 
Posts: 7358
|
 |
Re: RB4.TMP
« Reply #5 on: Feb 13th, 2009, 12:39am » |
Quote Modify
|
Very good. Combofix did some cleaning. Now please do the following: 1. Remove Combofix from your system. - Go to START>RUN and type in combofix /u (Note the space before /u) - Click on OK and let Combofix remove itself. 2. Update your Java which is severely out-of-date. For system security reasons, you should always run with latest Java. - Go to the link below and download/install the latest Java update which is Update 12. The file to download/install is named Java SE Runtime Environment (JRE)- JRE 6 Update 12 http://java.sun.com/javase/downloads/index.jsp - After you have installed the new update, it is important that you remove all the older updates of Java. Go to Control Panel>Add and Remove Programs and uninstall all the old Java Updates. You should end up with only Java Update 12 on your system. - OR you can follow the procedure in the link below to install/use utility JavaRa. This will make it easier to update Java and cleanup afterwards. http://www.misec.net/forum/board/FAQ/1216543051 3. Next you need to fix the O24 - Desktop Component on your system. - Go to Control Panel>Display>Desktop tab>Customize Desktop>Web tab - Uncheck and delete everything you find in there (except for "My current home page") - Remove the checkmark from the "Lock Desktop Items" box if it is checked. - Click on OK, then Apply and OK - Reboot your computer The above exercise should fix everything that I am seeing in the Hijackthis log that needs fixed. Your Hijackthis log is showing nothing malicious on your system. Now let's clean up unneeded junk and temporarily files from your system. A good freebie program for this program CCleaner. This is a program that you can run at any time to clean junk/temporary files off your system....you can do it 3-4 times a day if you like. - Go to the link below and download/install CCleaner v2.16.830 - Slim http://www.ccleaner.com/download/builds.aspx - Once you get it installed, open CCleaner and click on the Cleaner icon on the left icon bar. - Click on Analyze. CCleaner will then scan your system and display all the junk/temporary files it finds that can be removed. - To remove these unnecessary files, click on Run Cleaner. It will then clean your system. NOTE 1: I do not recommend that your use the Registry cleaning feature of CCleaner unless you are familiar with registry cleaners. Registry cleaning can cause damage to your system if it is not "supervised" by a knowledgeable user. NOTE 2: CCleaner has an option that permits you to remove all the uninstaller directories for Microsoft Hotfixes that you have installed via Windows Update. Each time a Microsoft hotfix is installed, an uninstaller directory is automatically created. These uninstaller directories occupy many, many megabytes of your disk space. Their purpose is to permit you to uninstall a Microsoft Hotfix if it does not work on your system. Have you ever needed to uninstall a Microsoft Hotfix? I rather doubt it. Therefore, you can reclaim all this disk space by removing the uninstaller directories. To do this: - Open CCleaner and click on the Cleaner icon - Under Advanced, check mark only the box that is labeled Hotfix Uninstallers - Click on Analyze to see what CCleaner is about to clean. - To clean, click on Run Cleaner. - Then uncheck the box labeled Hotfix Uninstallers The next time you use Windows Updates and install Microsoft Hotfixes/Updates, wait about a week to ensure that everything is okay following the updates. Then repeat the above to remove the Uninstaller directories. The User Forum for CCleaner is located here: http://forum.piriform.com/ Now, concerning RB4.TMP....... It is most likely that your AT&T Internet Security Suite is generating this file when you boot up your system. I've googled this file and have read several results that indicate this. - Have you just recently installed this security suite? - Is there a user support contact that you can email or call to ask if RB4.TMP is generated by the AT&T Internet Security Suite? BTW, in your Combofix log, the part shown below is nothing to worry about. It is part of your LexMark printer software and is okay. Quote:catchme 0.3.1367 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-02-12 18:09:31 Windows 5.1.2600 Service Pack 3 NTFS scanning hidden processes ... scanning hidden autostart entries ... HKLM\Software\Microsoft\Windows\CurrentVersion\Run LXCDCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXCDtime.dll,_RunDLLEntry@16? ? scanning hidden files ... scan completed successfully hidden files: 0 |
|
|
| « Last Edit: Feb 13th, 2009, 1:14am by siliconman01 » |
IP Logged |
______ TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
|
|
|