siliconman01
Global Moderator
    
 Trojans! Chew 'em Up, Spit 'em Out...
Gender: 
Posts: 7358
|
 |
Re: Help needed for virus removal please.
« Reply #3 on: Feb 6th, 2009, 2:14pm » |
Quote Modify
|
Okay, your Hijackthis log is not exposing anything malicious. However there are some items you need to take of. Please do the following: 1. Run another Hijackthis scan. When the scan is completed, place a check mark in the box next to the following item(s). BE SURE that these are the only times checked. O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file) O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab 2. Close your browser. 3. Click on Fix checked located at the bottom left of the Hijackthis window. Confirm that you want Hijackthis to fix these items and let it fix them. 4. Close Hijackthis and immediately reboot. 5. Once rebooted, you need to update your Java. It is several updates behind. For security reasons, it is important that you keep Java up-to-date. Go to the link below and download Java SE Runtime Environment (JRE), JRE 6 Update 12. Save it on your desktop. http://java.sun.com/javase/downloads/index.jsp 6. Close your browser and install JRE 6 Update 12 by double clicking on the Java icon that you just saved on your desktop. 7. Reboot after you have installed the Java update. 8. Once rebooted, you need to uninstall all old versions of Java. - Go to Control Panel>Add and Remove Programs and uninstall all Java Updates except Java Update 12 9. You can also delete the Update 12 installer that you saved on your desktop. Now we need to try to find what is causing the Avira detection. 1. Run the TrojanHunter LiveUpdate to ensure that you have the latest rulesets. 2. Open the TrojanHunter scanner GUI and click on the Options icon on the left icon bar. 3. Checkmark all the options except the very last one which is "Warn on executable files with double extensions" 4. Close TrojanHunter. 5. Reboot your computer into SAFE MODE 6. Run a full scan of your computer with TrojanHunter. Let it quarantine anything that it finds. 7. Once the scan is completed, reboot back into Normal Mode. 8. Post back here the scan report from the TrojanHunter scan. This report is located in folder Scan Reports at C:\Program Files\TrojanHunter 5.0\Scan Reports. 9. Post a new Hijackthis scan log. IF TrojanHunter did not find anything malicious during its scan, please do the following before posting the logs in Step 8 and 9 above. 1. Go to the link below and download/install the Free Version Home Users of SuperAntiSpyware. http://www.superantispyware.com/superantispywarefreevspro.html 2. Once you have it installed, go to the link below and download/install the latest detection rules for SuperAntispyware. http://www.superantispyware.com/definitions.html - Click on Download Installer and then follow the wizard to install the latest updates. 3. Reboot your computer back into SAFE MODE 4. Run a COMPLETE scan of your system with SuperAntiSpyware. Let it quarantine anything it finds. 5. Reboot back into Normal Mode 6. Then post the SuperAntiSpyware scan log, the TH scan report, and a new Hijackthis log.
|
|
IP Logged |
______ TrojanHunter V5.5.1002...No. 1 AT in my Book and on my Box(es)! Windows 7 x64 Professional on a Dell XPS 410, 8 gbyte RAM, dual WD VelociRaptors, dual 24" UltraSharp FPD monitors, Logitech 5.1 Surround Sound; Windows 7 x86 Professional on a Dell Vostro 220s, 4 gbyte RAM, dual WD VelociRaptors. Common: router, cable modem.
|
|
|