Completed 8 steps; trojan etc found

Status
Not open for further replies.
Had Symantec av corporate which could not clean the trojan and kept asking for restart.
If I click on temp internet files: "this page has an unspecified potential security risk"
 
When someone presents with the overload of programs and startups such as you have, it can be a time consuming task to go through all the entries.

1. Did you let Avira quarantine what it found? Did you delete the quarantined files?
2. Decide whether you want Symantec or Avira to be your antivirus program and remover the other. Having two AV programs can cause conflicts resulting in less protection, no more.

3. Please disable this program while we are cleaning:
C:\PROGRA~1\Agnitum\TAUSCA~1.6\taumon.exe
"Tauscan is a powerful Trojan Horse detection and removal engine capable of catching every known type of backdoor that can threaten your system."
O4 - HKLM\..\Run: [Tau Monitor] C:\PROGRA~1\Agnitum\TAUSCA~1.6\taumon.exe
Complete the antivirus uninstall for the program you don't want to keep and disable the Tauscan program> then>>
4. Remove bad HijackThis entries
• Run HijackThis
• Click on the System Scan Only button
Put a check beside all of the items listed below (if present):

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
(NOTE: if you have set a homepage to com up as a blank page, you may leave this entry. If you have not, it is the About:Blank malware)
O3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)
(Did you set restrictions? IF not, they are from the malware)
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
Close all open windows and browsers/email, etc...
• Click on the "Fix Checked" button

• When completed, close the application and reboot.

Please update and rescan with Malwarebytes, SuperAntispyware, follow with new scan for HijackThis. Attach the new logs. Be sure you have addressed #1, 2 and 3 in the beginning of this post first.
 
Status
Not open for further replies.
Back