Saved Bookmarks
| 1. |
Solve : virus, trojans, malware oh my....? |
|
Answer» after the combofix restarted i got a mcafee waring about something called RemAdm-ProcLaunch!171 in folder c:\327882r2fwjfw\psexec.cfexe after the combofix restarted i got a mcafee waring about something called RemAdm-ProcLaunch!171 in folder c:\327882r2fwjfw\psexec.cfexe Yes that's part of ComboFix, which is why we suggest turning off the AV before running it. ComboFix uses scripts that are seen as malicious by antivirus. Kind of like the old saying "you have to fight fire with fire." Double click FindAWF.exe to start the tool.
"C:\Program Files\iTunes\bak\iTunesHelper.exe" "C:\Program Files\QuickTime\bak\qttask.exe" "C:\WINDOWS\SYSTEM32\bak\ctfmon.exe" "C:\WINDOWS\SYSTEM32\bak\hkcmd.exe" "C:\WINDOWS\SYSTEM32\bak\igfxpers.exe" "C:\WINDOWS\SYSTEM32\bak\igfxtray.exe" "C:\Program Files\HP\hpcoretech\bak\hpcmpmgr.exe" "C:\Program Files\Intel\Modem Event Monitor\bak\IntelMEM.exe" "C:\WINDOWS\SYSTEM32\dla\bak\tfswctrl.exe" "C:\Program Files\Adobe\Acrobat 7.0\Reader\bak\AdobeUpdateManager.exe" "C:\Program Files\Common Files\AOL\ACS\bak\AOLDial.exe" "C:\Program Files\Common Files\Sonic\Update Manager\bak\sgtray.exe" "C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\bak\GoogleToolbarNotifier.exe" "C:\Program Files\Java\jre1.5.0_10\bin\bak\jusched.exe"
[recovering disk space -- attachment deleted by admin]Getting closer. Double-click FindAWF.exe to start the tool.
C:\PROGRA~1\ITUNES\BAK C:\PROGRA~1\MESSEN~1\BAK C:\PROGRA~1\QUICKT~1\BAK C:\WINDOWS\SYSTEM32\BAK C:\PROGRA~1\COMMON~1\WRUM\BAK C:\PROGRA~1\HP\HPCORE~1\BAK C:\PROGRA~1\INTEL\MODEME~1\BAK C:\WINDOWS\SYSTEM32\DLA\BAK C:\PROGRA~1\ADOBE\ACROBA~2.0\READER\BAK C:\PROGRA~1\COMMON~1\AOL\ACS\BAK C:\PROGRA~1\COMMON~1\SONIC\UPDATE~1\BAK C:\PROGRA~1\GOOGLE\GOOGLE~2\121128~1.546\BAK C:\PROGRA~1\JAVA\JRE15~1.0_1\BIN\BAK
[recovering disk space -- attachment deleted by admin]Note: the below instructions were created specifically for this user. If you are not this user, DO NOT follow these directions as they could damage the workings of your system Now download The Avenger by Swandog46 and save it to your Desktop.
Folders to delete: C:\PROGRA~1\COMMON~1\AOL\ACS\BAK
---------- Last step with FindAWF Double-click FindAWF.exe to start the tool.
Download ResetProtocolDefaults to your desktop. Double click ResetProtocolDefaults.reg and answer Yes to any prompts and allow it to merge into the Registry. ---------- Download OTCleanIt.exe and save it to your Desktop.
----- Go to:
When prompted select the C: drive and click OK. Check the boxes for:
Click OK or Enter ---------- Use the Kaspersky Online Scanner In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon and choose Run as Administrator. Click on SCAN NOW Click on the Accept button and install any components it NEEDS.
Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.OTMoveIt has encountered a problem and needs to close. does it everytime i try to open it, about 1 sec into itIs this when you are trying to enter the text into it?no trying to launch itI know. There is two sets of instructions for OTMoveIt2. Did you do the first step in entering the text and clicking MoveIt or is it the second when trying to run the CleanUp option?I downloaded it, dbl click to open and it crashes, i never get to imput the textOk thats what I needed to know. I just edited the post with NEW directions to use another program.otcleanit will not launch when i dbl click it, same error mesg.Lets try one more. Download http://download.bleepingcomputer.com/oldtimer/OTScanIt.exe Unzip it to the Desktop, open the folder and then open OTScanIt.exe Click the CleanUp button and start the cleanup process. Choose NOT to restart now. Close OTCleanIt and then re-open it and click the CleanUp button again and start the cleanup process. This time re-start the computer when prompted. |
|