Noob Help - Setup.exe and Autorun.inf

Status
Not open for further replies.

GBE300

Posts: 21   +0
Before you ask me to read I have.

I have read a few posts about this issue, but I still need some help.

Has this been solved? And if so is it possible to ask for a step by step with links for the programs I may need to use. I am a total noob and I have gotten lost with the list of do this and do that.

The next thing is I am currently running under windows 64bit edition. What should I do?

Some other information. Yes I have fully scanned and updated and ran the following in this order:

Avast - Updated, Full system
Ad-aware - same
Spybot search and destroy - Same
Spyware Blaster - Updated and Enabled all protections
Avast - update, full scan.

Restarted to safe mode.
Adaware, SpyBot, Spyware Blaster
Enabled Medium protection on Nvidia's Firewall
I set up the following settings for the programs It caught. (see attached file Firewall denies.jpg)
Temp folder was cleaned and deleted - trash emptied
I could find no other references of the setup or the autorun

Restarted in normal mode. They are back.

Thanks for any help. I have not used the tools HJT or anything please point me in the right direction of what to read to use them correctly if I need to use them. Thanks for any help, I have two systems (one 64bit and one xp pro) not sure where the hell this came from but I would love to have a few minutes with the writer... This is the first time I have seen these and the first time I am asking for help. Thanks in advance.

GBE300

File Link - Leads to a jpg of the fire wall settings: http://images.myphotoalbum.com/g/gb/gbe/gbe3/gbe30/gbe300/albums/album02/Firewall_Denies.thumb.jpg
 
Sorry just now reading the read me posts. Sorry. I will follow whats in there and post a HJT asap.
 
hjt file

Here is the HJT file. Thanks for the help.

I have run kasperkey and bit defender. I could not, run ewido as it did not run on 64 bit.

Thanks for the help, going to shut down and start again in the morning.

C
 
Hello and welcome to Techspot.

Your HJT log appears to be clean. However I can`t tell for sure as I`m not familiar with 64 bit Windows.

Have you tried the Pocket Killbox programme to delete the files? You can get it HERE.

Regards Howard :wave: :wave:

This thread is for the use of GBE300 only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our security and the web forum.
 
Thanks howard. I will try Killbox when I get home this evening. My machine is definitely still infected. I had about 4-5 more of the ##es*** files in my temp folder again this morning when I started up to check this board.

I will see what the status is again later and See if it is still happening. I am thinking a full reformat and install may just be easier. Oh and dumping 64 for Pro...

Going to look around the site today. Can any one point me to some good posts on prevention practices and solid programs to use to help clean and prevent these type of things?

Thanks.
C.
 
I have looked it over and its the reason I made my post. The main issue is that I am running Windows 64 not XP.... I will most likely be changing this when I get home and reformatting/reinstalling XP pro in the machine in question.

If its clean and I can get it all set up (firewalled and such). I will then start on getting help with my current XP Pro machine that also has this same problem. Thanks for everyone's input and help.
 
Thanks all for your help. I will most likely be starting 2 more threads, one with some data questions and another on this bug on a pc I can't reformat. (not till I backup data which I need to clean first).

For this machine I reformatted and reinstalled windows XP. 64Bit was making it alot harder for me to do anything and I did not like seeing 50+ running processes.

I followed the advice thruogh these boards and seriously secured myself on this new installation. Thanks for being a wealth of knowledge for anyone that needs it. Thanks to the Admin team here for all you do.
 
Status
Not open for further replies.
Back