Your tip about ‘Trojan Remover’ is appreciated.
Code:
C:\WINDOWS\system32\[B]yqrocd.dll[/B] (Trojan.Vundo.H) -> Delete on reboot.
MBAB did not handle all that it found until the computer restart.
It appears that the infection is mostly handled.
Rescan with MBAB & SAS (run as pairs) until clean or something that cannot be cleaned.
HJT scan informs what has not been handled (computer restart before HJT scan)
Caught by HJT.
Code:
O20 - AppInit_DLLs: [B]yqrocd.dll [/B]+ valid
[LIST]
[*]Confirm file has been deleted.
[*]'Regedit' can be used to delete references to file
[*]Or wait for updated MBAM to clean this reference.
[/LIST]
Additional finding -
- Source for this not understood
- User choice - removal recommended
- R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=localhost:8777;https=localhost:8777
If symptoms remain, post new logs and describe conditions.
Following clean scans establish a clean restore point.
Establish a new clean restore point and Clear your existing System Restore points:
- New
- Go to Start > All Programs > Accessories > System Tools > System Restore>
- Select Create a restore point> OK.
- Clear Old
- go to Start > Run > cleanmgr > Select the More options tab >
- Choose the option to clean up System Restore > OK
This will remove all restore points except the new one you just created.