TechSpot

Can not remove Trojan

Solved
By Troyce Brooks
Oct 27, 2012
Topic Status:
Not open for further replies.
  1. Troyce Brooks

    Troyce Brooks TS Rookie Topic Starter Posts: 20

    Here's the latest. Seems to have rebooted just fine. Thanks

    All processes killed
    ========== OTL ==========
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cca2e567-1987-4100-a3c6-5b4267084510}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AFBCB7E0-F91A-4951-9F31-58FEE57A25C4}\ not found.
    Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{cca2e567-1987-4100-a3c6-5b4267084510}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cca2e567-1987-4100-a3c6-5b4267084510}\ not found.
    Prefs.js: ddaldjizbp@ddaldjizbp.org:2.5 removed from extensions.enabledAddons
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\ddaldjizbp@ddaldjizbp.org.xpi moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\components folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\whatsnew folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames\fg folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames\bg folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\topgames folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\options folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames\fg folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames\bg folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\newgames folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\panels folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton\icons folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\weatherbutton folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\uwa folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio\images folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio\css folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\radio folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\images folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\scripts folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\images folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default\css folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\default folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels\css folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib\panels folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\lib folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin\bigfishgames folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\skin folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\modules folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\lib folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data\search folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data\feeds folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content\data folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome\content folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692}\chrome folder moved successfully.
    C:\Users\RoseyB\AppData\Roaming\Mozilla\Firefox\Profiles\yzit0tbc.default\extensions\{6847DFAE-037A-400c-A524-27F0A281B692} folder moved successfully.
    Prefs.js: {6847DFAE-037A-400c-A524-27F0A281B692}:2.2 removed from extensions.enabledAddons
    Prefs.js: {6847DFAE-037A-400c-A524-27F0A281B692}:2.2 removed from extensions.enabledItems
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{0CF7685E-757D-4B78-84C0-713A40E92C2f}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0CF7685E-757D-4B78-84C0-713A40E92C2f}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found.
    Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{C7C9FC25-88B0-4682-9C9F-2608E9117647}\ deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C7C9FC25-88B0-4682-9C9F-2608E9117647}\ deleted successfully.
    C:\Program Files (x86)\bfgbartb\BfgBarDx.dll moved successfully.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{C7C9FC25-88B0-4682-9C9F-2608E9117647} deleted successfully.
    Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C7C9FC25-88B0-4682-9C9F-2608E9117647}\ not found.
    File C:\Program Files (x86)\bfgbartb\BfgBarDx.dll not found.
    Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
    C:\ProgramData\bobipandkcjsylf folder moved successfully.
    C:\Users\RoseyB\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini moved successfully.
    C:\ProgramData\yeplmhpycrkhtgt moved successfully.
    ADS C:\ProgramData\TEMP:2B40A7DB deleted successfully.
    ADS C:\ProgramData\TEMP:E8AEB2BF deleted successfully.
    ADS C:\ProgramData\TEMP:A71DCB33 deleted successfully.
    ADS C:\ProgramData\TEMP:6A9CA6CB deleted successfully.
    ADS C:\ProgramData\TEMP:2CB9631F deleted successfully.
    ADS C:\ProgramData\TEMP:2E636DD9 deleted successfully.
    ADS C:\ProgramData\TEMP:934CA750 deleted successfully.
    ADS C:\ProgramData\TEMP:95D421DF deleted successfully.
    ADS C:\ProgramData\TEMP:5E73E1C2 deleted successfully.
    ADS C:\ProgramData\TEMP:4C9782FB deleted successfully.
    ADS C:\ProgramData\TEMP:120B3AFD deleted successfully.
    ADS C:\ProgramData\TEMP:94A31742 deleted successfully.
    ADS C:\ProgramData\TEMP:6DD124E2 deleted successfully.
    ADS C:\ProgramData\TEMP:C6920A5D deleted successfully.
    ADS C:\ProgramData\TEMP:0E22C5DB deleted successfully.
    ADS C:\ProgramData\TEMP:12258D63 deleted successfully.
    ADS C:\ProgramData\TEMP:084612C9 deleted successfully.
    ADS C:\ProgramData\TEMP:93F3E4C9 deleted successfully.
    ADS C:\ProgramData\TEMP:1A15E356 deleted successfully.
    ADS C:\ProgramData\TEMP:8E5EA40F deleted successfully.
    ADS C:\ProgramData\TEMP:5FC043A8 deleted successfully.
    ADS C:\ProgramData\TEMP:70E897B5 deleted successfully.
    ADS C:\ProgramData\TEMP:53B8C5D2 deleted successfully.
    ADS C:\ProgramData\TEMP:E732B44B deleted successfully.
    ADS C:\ProgramData\TEMP:3D4B733E deleted successfully.
    ADS C:\ProgramData\TEMP:FBA79096 deleted successfully.
    ADS C:\ProgramData\TEMP:58E38390 deleted successfully.
    ADS C:\ProgramData\TEMP:1B96CF22 deleted successfully.
    ADS C:\ProgramData\TEMP:A3B8F70C deleted successfully.
    ADS C:\ProgramData\TEMP:10CB85CA deleted successfully.
    ADS C:\ProgramData\TEMP:A9562832 deleted successfully.
    ADS C:\ProgramData\TEMP:6294B369 deleted successfully.
    ADS C:\ProgramData\TEMP:E6C6EB3B deleted successfully.
    ADS C:\ProgramData\TEMP:53BA2DF6 deleted successfully.
    ADS C:\ProgramData\TEMP:F89F2593 deleted successfully.
    ADS C:\ProgramData\TEMP:BEE39E9B deleted successfully.
    ADS C:\ProgramData\TEMP:2AE74FF9 deleted successfully.
    ADS C:\ProgramData\TEMP:4EFA2FC7 deleted successfully.
    ADS C:\ProgramData\TEMP:25249477 deleted successfully.
    ADS C:\ProgramData\TEMP:FAB64002 deleted successfully.
    ADS C:\ProgramData\TEMP:4A448DB2 deleted successfully.
    ADS C:\ProgramData\TEMP:EC2381A4 deleted successfully.
    ADS C:\ProgramData\TEMP:BDCD8531 deleted successfully.
    ADS C:\ProgramData\TEMP:C22674B6 deleted successfully.
    ADS C:\ProgramData\TEMP:927EC486 deleted successfully.
    ADS C:\ProgramData\TEMP:55F44B88 deleted successfully.
    ADS C:\ProgramData\TEMP:206470A5 deleted successfully.
    ADS C:\ProgramData\TEMP:FAFEC4B9 deleted successfully.
    ADS C:\ProgramData\TEMP:BCFEA004 deleted successfully.
    ADS C:\ProgramData\TEMP:E4EE99EF deleted successfully.
    ADS C:\ProgramData\TEMP:AD2DB2F9 deleted successfully.
    ADS C:\ProgramData\TEMP:4911BB5C deleted successfully.
    ADS C:\ProgramData\TEMP:ECFD9449 deleted successfully.
    ADS C:\ProgramData\TEMP:6F55EB66 deleted successfully.
    ADS C:\ProgramData\TEMP:D31BE97C deleted successfully.
    ADS C:\ProgramData\TEMP:F84B8DB5 deleted successfully.
    ADS C:\ProgramData\TEMP:CBAF0C30 deleted successfully.
    ADS C:\ProgramData\TEMP:6A0A47E7 deleted successfully.
    ADS C:\ProgramData\TEMP:EC3A9923 deleted successfully.
    ADS C:\ProgramData\TEMP:2F141B68 deleted successfully.
    ADS C:\ProgramData\TEMP:CB0EB1DE deleted successfully.
    ADS C:\ProgramData\TEMP:A4AF8D0D deleted successfully.
    ADS C:\ProgramData\TEMP:7A0EFE63 deleted successfully.
    ADS C:\ProgramData\TEMP:4DCAC4BC deleted successfully.
    ADS C:\ProgramData\TEMP:14362DF8 deleted successfully.
    ADS C:\ProgramData\TEMP:A4F63AED deleted successfully.
    ADS C:\ProgramData\TEMP:12F3508C deleted successfully.
    ADS C:\ProgramData\TEMP:43301D1D deleted successfully.
    ADS C:\ProgramData\TEMP:0AC32449 deleted successfully.
    ADS C:\ProgramData\TEMP:E51234A9 deleted successfully.
    ADS C:\ProgramData\TEMP:0ED4AC2F deleted successfully.
    ADS C:\ProgramData\TEMP:260575F1 deleted successfully.
    ADS C:\ProgramData\TEMP:FB97DB91 deleted successfully.
    ADS C:\ProgramData\TEMP:462A7C89 deleted successfully.
    ADS C:\ProgramData\TEMP:88E3B9B6 deleted successfully.
    ADS C:\ProgramData\TEMP:5ACE199E deleted successfully.
    ADS C:\ProgramData\TEMP:EFBD4447 deleted successfully.
    ADS C:\ProgramData\TEMP:E265ED33 deleted successfully.
    ADS C:\ProgramData\TEMP:2636DE16 deleted successfully.
    ADS C:\ProgramData\TEMP:CAE2C3A5 deleted successfully.
    ADS C:\ProgramData\TEMP:0F64164E deleted successfully.
    ADS C:\ProgramData\TEMP:3BC173E4 deleted successfully.
    ADS C:\ProgramData\TEMP:E2CFA9CD deleted successfully.
    ADS C:\ProgramData\TEMP:A384652A deleted successfully.
    ADS C:\ProgramData\TEMP:A3E39C6A deleted successfully.
    ========== FILES ==========
    < ipconfig /flushdns /c >
    Windows IP Configuration
    Successfully flushed the DNS Resolver Cache.
    C:\Users\RoseyB\Downloads\cmd.bat deleted successfully.
    C:\Users\RoseyB\Downloads\cmd.txt deleted successfully.
    ========== COMMANDS ==========

    [EMPTYTEMP]

    User: All Users

    User: Default
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 67 bytes

    User: Default User
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 0 bytes

    User: Public
    ->Temp folder emptied: 0 bytes

    User: RoseyB
    ->Temp folder emptied: 0 bytes
    ->Temporary Internet Files folder emptied: 2441618 bytes
    ->Java cache emptied: 582740981 bytes
    ->FireFox cache emptied: 267640314 bytes
    ->Flash cache emptied: 112043 bytes

    %systemdrive% .tmp files removed: 0 bytes
    %systemroot% .tmp files removed: 0 bytes
    %systemroot%\System32 .tmp files removed: 0 bytes
    %systemroot%\System32 (64bit) .tmp files removed: 0 bytes
    %systemroot%\System32\drivers .tmp files removed: 0 bytes
    Windows Temp folder emptied: 0 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 66784 bytes
    %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 0 bytes
    RecycleBin emptied: 122151 bytes

    Total Files Cleaned = 814.00 mb


    OTL by OldTimer - Version 3.2.69.0 log created on 11042012_211903

    Files\Folders moved on Reboot...
    File\Folder C:\Users\RoseyB\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

    PendingFileRenameOperations files...

    Registry entries deleted on Reboot...
  2. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Good. :D Please do the following again...

    ESET Online Scan

    Please run a free online scan with the ESET Online Scanner
    • Tick the box next to YES, I accept the Terms of Use
    • Click Start
    • When asked, allow the ActiveX control to install, or it will ask to download an installer. Please do so an install it.
    • Click Start or wait for the scanner to load.
    • Make sure that the options Remove found threats and the option Scan unwanted applications are checked.
    • Click Scan (This scan can take several hours, so please be patient)
    • Once the scan is completed, there are a couple of things to keep in mind:
    • 1. If NO threats were found, allow the scanner to Uninstall on close and then close the Window.
    • 2. If threats WERE detected, click on List of Threats Found, Export to Text File...save it as ESET-Scan-Log.txt. Click the back button/link, put a checkmark to Uninstall Application on Close and then close the window.
    • Open the logfile from wherever you saved it
    • Copy and paste the contents in your next reply.
  3. Troyce Brooks

    Troyce Brooks TS Rookie Topic Starter Posts: 20

    Here is the EST file


    C:\Users\RoseyB\AppData\Local\Temp\0.7678232558540422 Win32/Olmarik.AYD trojan cleaned by deleting - quarantined
  4. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Hi there. It all appears to be good, so we will finish up to make sure your computer is protected from malware in the future.

    Clean up System Restore

    Now, to get you off to a clean start, we will be creating a new Restore Point, then clearing the old ones to make sure you do not get reinfected, in case you need to "restore back."

    To manually create a new Restore Point
    • Go to Control Panel and select System and Maintenance
    • Select System
    • On the left select Advance System Settings and accept the warning if you get one
    • Select System Protection Tab
    • Select Create at the bottom
    • Type in a name I.e. Clean
    • Select Create
    Now we can purge the infected ones
    • Go back to the System and Maintenance page
    • Select Performance Information and Tools
    • On the left select Open Disk Cleanup
    • Select Files from all users and accept the warning if you get one
    • In the drop down box select your main drive I.e. C
    • For a few moments the system will make some calculations:
      [​IMG]
    • Select the More Options tab
      [​IMG]
    • In the System Restore and Shadow Backups select Clean up
      [​IMG]
    • Select Delete on the pop up
    • Select OK
    • Select Delete
    Run OTC to remove our tools

    To remove all of the tools we used and the files and folders they created, please do the following:
    Please download OTC.exe by OldTimer:
    • Save it to your Desktop.
    • Double click OTC.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    Note:If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.

    Purge old temporary files

    NOTE: If you already have this installed, you don't have to reinstall it.

    Please download CCleaner Slim and save it to your Desktop - Alternate download link

    When the file has been saved, go to your Desktop and double-click on ccsetupxxx_slim.exe
    Follow the prompts to install the program.

    • Double-click the CCleaner shortcut on the desktop to start the program.
    • A prompt will ask you if you want CCleaner to do a check to see what cookies it needs to keep. Allow that operation.
    • On the Cleaner tab, click on Run Cleaner on the bottom-right to run the program.
    • Important: Make sure that ALL browser windows are closed before selecting Run Cleaner, or it will ask if you want the program to close them for you (when you do this, all unsaved data may be lost in the browser).

      Caution: Only use the Registry feature if you are very familiar with the registry.
      Always back up your registry before making any changes. Exit CCleaner after it has completed it's process.

      Security Check

      Please download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
      • Save it to your Desktop.
      • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
      • A Notepad document should open automatically called checkup.txt; please post the contents of that document.
  5. Troyce Brooks

    Troyce Brooks TS Rookie Topic Starter Posts: 20

    Here we go. Computer certainly seems to be running faster, mine seems quite slow compared to this one.

    Results of screen317's Security Check version 0.99.54
    Windows 7 Service Pack 1 x64 (UAC is enabled)
    Internet Explorer 8 Out of date!
    ``````````````Antivirus/Firewall Check:``````````````
    Windows Firewall Enabled!
    Norton Security Suite
    WMI entry may not exist for antivirus; attempting automatic update.
    `````````Anti-malware/Other Utilities Check:`````````
    Treasure Seekers: Follow the Ghosts
    Malwarebytes Anti-Malware version 1.65.1.1000
    Java(TM) 7
    Java version out of Date!
    Adobe Flash Player 10 Flash Player out of Date!
    Adobe Reader 9 Adobe Reader out of Date!
    Mozilla Firefox (16.0.2)
    ````````Process Check: objlist.exe by Laurent````````
    Norton ccSvcHst.exe
    `````````````````System Health check`````````````````
    Total Fragmentation on Drive C: 1%
    ````````````````````End of Log``````````````````````
  6. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Java Update!

    Please download the newest version of Java from Java.com.

    Before installing: it is important to remove older versions of Java since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Java. (J2SE Runtime Environment). Please uninstall/remove each of them.

    Once old versions are gone, please install the newest version.

    Read more about Java exploit problems

    Adobe Flash Player Update!

    Please download the newest version of Adobe Flash Player from Adobe.com

    Before installing: it is important to remove older versions of Flash Player since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Adobe Flash Player. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.

    Adobe Reader Update!

    Please download the newest version of Adobe Acrobat Reader from Adobe.com

    Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
    Go to the Control Panel and enter Add or Remove Programs (Programs and Features in Vista/7).
    Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

    Once old versions are gone, please install the newest version.


    Personal Tips on Preventing Malware

    See this page for more info about malware and prevention.


    Any other questions before I mark this topic solved?
  7. Jay Pfoutz

    Jay Pfoutz Malware Helper Posts: 4,286   +49

    Topic marked solved. :)
Topic Status:
Not open for further replies.


Add New Comment

TechSpot Members
Login or sign up for free,
it takes about 30 seconds.
You may also...


Get complete access to the TechSpot community. Join thousands of technology enthusiasts that contribute and share knowledge in our forum. Get a private inbox, upload your own photo gallery and more.