Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Trojan removal - Thx for your help  (Read 29369 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Trojan removal - Thx for your help
« Reply #30 on: November 25, 2011, 04:55:41 PM »

I'd like to scan your machine with ESET OnlineScan

•Hold down Control and click on the following link to open ESET OnlineScan in a new window.
ESET OnlineScan
•Click the button.
•For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
  • Click on to download the ESET Smart Installer. Save it to your desktop.
  • Double click on the icon on your desktop.
•Check
•Click the button.
•Accept any security warnings from your browser.
•Check
•Push the Start button.
•ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
•When the scan completes, push
•Push , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
•Push the button.
•Push
A log file will be saved here: C:\Program Files\ESET\ESET Online Scanner\log.txt
Windows 8 and Windows 10 dual boot with two SSD's

cian31

    Topic Starter


    Rookie

    • Experience: Familiar
    • OS: Windows Vista
    Re: Trojan removal - Thx for your help
    « Reply #31 on: November 28, 2011, 12:50:30 AM »
    Hi superdave!
    The last scan with ESET don't give me the option you mentionned : "list of found threats"
    This is due I think that the scan end on a "no threat found" message.

    The log on the C: said :
    Quote
    ESETSmartInstaller@High as CAB hook log:
    OnlineScanner.ocx - registred OK

    SuperDave

    • Malware Removal Specialist


    • Genius
    • Thanked: 1020
    • Certifications: List
    • Experience: Expert
    • OS: Windows 10
    Re: Trojan removal - Thx for your help
    « Reply #32 on: November 28, 2011, 01:33:01 PM »
    Just to be sure, let's try this one.

    Run the BitDefender Online scanner

    Agree to the license and then select Scan. DO NOT CHANGE THE OPTIONS TO SHOW ALL FILES SCANNED. That will make your logs huge and we don't need to see clean files.

    Once Bitdefender completes the scan:
    Click-on the Detected Problems tab.
    Then select Click here to export the scan report.

    When the window comes up to save the report, change the Save as type: box to:
    Text (Tab Delimited) (*.txt) and then in the File name box enter change to bdscan then click Save.

    This will save a file named bdscan.txt. I would suggest saving it to the Desktop so you can easily find it. (take notice of where you save it so you can find it later).
    This bdcan.txt file will actually contain HTML code that we can easily view later while reviewing your log. All we have to do is rename the file to bdscan.html.

    If you do not follow these step, you will have an incorrect log or worse a log summary which is useless to us.

    Post the bdscan.txt file as an Attachment.
    Windows 8 and Windows 10 dual boot with two SSD's

    cian31

      Topic Starter


      Rookie

      • Experience: Familiar
      • OS: Windows Vista
      Re: Trojan removal - Thx for your help
      « Reply #33 on: November 28, 2011, 02:23:30 PM »
      Hi superDave!
      Are you sure of these steps ? Because I don't have the same options/steps you describe ...

      When I am on BitDefender online scanner, I clic on the big green button named "start scanner".
      A new tab open on firefox, opens a new web site "http://quickscan.bitdefender.com/en/"
      A new green button "free scan now" appears on this new web site. I clic on it and a download begin. Then the scan can begin.
      At the end of the scan I got "
      Your computer is not infected
      Share the power of the Bitdefender engines.
      Recommend us to your friends!
      View report"

      Here is the log that appears


      QuickScan Beta 32-bit v0.9.9.99
      -------------------------------
      Scan date:  Mon Nov 28 22:20:12 2011
      Machine ID: 104AD72C



      No infection found.
      -------------------



      Processes
      ---------
      (unsigned)  Spyware Terminator                       4292    C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe

      (verified)   hpwuSchd Application                    3788    C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
      (verified)  AntiVir Desktop                          3736    C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      (verified)  Crawler Toolbar                          4992    C:\PROGRA~1\Crawler\Toolbar\CToolbar.exe
      (verified)  CyberLink MediaLibray Service            3584    C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
      (verified)  CyberLink PowerCinema                    3568    C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
      (verified)  Firefox                                  5092    C:\Program Files\Mozilla Firefox\firefox.exe
      (verified)  Firefox                                   452    C:\Program Files\Mozilla Firefox\plugin-container.exe
      (verified)  Firefox                                  2424    C:\Program Files\Mozilla Firefox\plugin-container.exe
      (verified)  Firefox                                  4476    C:\Program Files\Mozilla Firefox\plugin-container.exe
      (verified)  Google Talk Plugin                       4728    C:\Users\Cecile\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
      (verified)  HP DVDSmart                              3528    C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
      (verified)  HP MediaSmart                            3640    C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
      (verified)  HP MediaSmart TV                         3604    C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
      (verified)  HP Quick Launch Buttons                  3652    C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
      (verified)  HP Wireless Assistant                    3672    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      (verified)  HP Wireless Assistant                    1240    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
      (verified)  HpqToaster Module                        3484    C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
      (verified)  IDT PC Audio                             3728    C:\Program Files\IDT\WDM\sttray.exe
      (verified)  LightScribe                              3912    C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      (verified)  McAfee Security Scanner                  4032    C:\Program Files\McAfee Security Scan\2.0.181\SSScheduler.exe
      (verified)  Microsoft® Windows® Operating System      124    C:\Windows\ehome\ehmsas.exe
      (verified)  Microsoft® Windows® Operating System     3980    C:\Windows\ehome\ehtray.exe
      (verified)  Microsoft® Windows® Operating System     2472    C:\Windows\System32\conime.exe
      (verified)  Synaptics Pointing Device Driver         3520    C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      (verified)  Système d'exploitation Microsoft® Windo  2072    C:\Program Files\Internet Explorer\ieuser.exe
      (verified)  Système d'exploitation Microsoft® Windo  2708    C:\Windows\explorer.exe
      (verified)  Système d'exploitation Microsoft® Windo  2668    C:\Windows\System32\dwm.exe
      (verified)  Système d'exploitation Microsoft® Windo  2736    C:\Windows\System32\taskeng.exe
      (verified)  Windows® Internet Explorer               4712    C:\Program Files\Internet Explorer\iexplore.exe


      Network activity
      ----------------
      Process iexplore.exe (4712) connected on port 80 (HTTP) --> 93.184.71.2
      Process firefox.exe (5092) connected on port 443 (HTTP over SSL) --> 74.125.39.17
      Process firefox.exe (5092) connected on port 443 (HTTP over SSL) --> 209.85.148.18
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 46.33.71.9
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 173.194.35.35
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 69.171.242.40
      Process firefox.exe (5092) connected on port 443 (HTTP over SSL) --> 69.171.242.40
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 66.235.142.57
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 66.235.142.57
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 173.194.35.35
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 66.235.142.57
      Process firefox.exe (5092) connected on port 80 (HTTP) --> 66.235.142.57

      Process SpywareTerminatorUpdate.exe (4292) listens on ports: 6881 (BitTorrent)


      Autoruns and critical files
      ---------------------------
      (unsigned)  QuickTime                                C:\Program Files\QuickTime\QTTask.exe
      (unsigned)  Spyware Terminator                       C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe

      (verified)   hpwuSchd Application                    C:\Program Files\Hp\HP Software Update\hpwuschd2.exe
      (verified)  Adobe Acrobat                            C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe
      (verified)  Adobe Reader and Acrobat Manager         C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe
      (verified)  AntiVir Desktop                          C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
      (verified)  Catalyst® Control Center                 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe
      (verified)  CyberLink MediaLibray Service            C:\Program Files\Hewlett-Packard\TouchSmart\Media\Kernel\CLML\CLMLSvc.exe
      (verified)  CyberLink PowerCinema                    C:\Program Files\Hewlett-Packard\TouchSmart\Media\TSMAgent.exe
      (verified)  Flash® Player Installer/Uninstaller      C:\Windows\system32\Macromed\Flash\FlashUtil10o_Plugin.exe
      (verified)  Google Update                            C:\Users\Cecile\AppData\Local\Google\Update\GoogleUpdate.exe
      (verified)  HP DVDSmart                              C:\Program Files\Hewlett-Packard\Media\DVD\DVDAgent.exe
      (verified)  HP MediaSmart                            C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe
      (verified)  HP MediaSmart TV                         C:\Program Files\Hewlett-Packard\Media\TV\TVAgent.exe
      (verified)  HP Quick Launch Buttons                  C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCtrl.exe
      (verified)  HP Total Care Advisor                    C:\Program Files\Hewlett-Packard\HP Advisor\HPAdvisor.exe
      (verified)  HP Wireless Assistant                    C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
      (verified)  IDT PC Audio                             C:\Program Files\IDT\WDM\sttray.exe
      (verified)  LightScribe                              C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe
      (verified)  Microsoft® Windows® Operating System     C:\Windows\ehome\ehtray.exe
      (verified)  SuperAntiSpyware                         c:\program files\superantispyware\sasseh.dll
      (verified)  SUPERAntiSpyware WinLogon Processor      C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL
      (verified)  Synaptics Pointing Device Driver         C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
      (verified)  Système d'exploitation Microsoft® Windo  C:\Windows\system32\BROWSEUI.dll
      (verified)  Système d'exploitation Microsoft® Windo  C:\Windows\system32\logon.scr
      (verified)  Système d'exploitation Microsoft® Windo  c:\windows\system32\userinit.exe
      (verified)  Windows® Internet Explorer               c:\windows\system32\webcheck.dll


      Browser plugins
      ---------------
      (unsigned)  Crawler Toolbar                          C:\Program Files\Crawler\Toolbar\ctbr.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
      (unsigned)  QuickTime Plug-in 7.6.9                  C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
      (unsigned)  VLC Multimedia Plug-in                   C:\Program Files\VideoLAN\VLC\npvlc.dll

      (verified)  AcroIEHelperShim Library                 C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
      (verified)  Adobe Acrobat                            C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll
      (verified)  Adobe Acrobat                            C:\Program Files\Internet Explorer\plugins\nppdf32.dll
      (verified)  Adobe Acrobat                            C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll
      (verified)  BitDefender QuickScan                    C:\Users\Cecile\AppData\Roaming\Mozilla\Firefox\Profiles\wa878qin.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll
      (verified)  Google Talk Plugin                       C:\Users\Cecile\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
      (verified)  Google Talk Plugin Video Accelerator     C:\Users\Cecile\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
      (verified)  Google Update                            C:\Users\Cecile\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll
      (verified)  Java Deployment Toolkit 6.0.200.2        C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll
      (verified)  Java(TM) Platform SE 6 U20               C:\Program Files\Java\jre6\bin\jp2ssv.dll
      (verified)  Java(TM) Platform SE 6 U20               C:\Program Files\Java\jre6\bin\ssv.dll
      (verified)  Microsoft® Windows Media Player Firefox  C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll
      (verified)  Microsoft® Windows® Operating System     C:\Windows\system32\NLAapi.dll
      (verified)  Microsoft® Windows® Operating System     C:\Windows\System32\winrnr.dll
      (verified)  nppdf32.FRA                              C:\Program Files\Internet Explorer\plugins\nppdf32.FRA
      (verified)  nppdf32.FRA                              C:\Program Files\Mozilla Firefox\plugins\nppdf32.FRA
      (verified)  NPSWF32.dll                              C:\Windows\system32\Macromed\Flash\NPSWF32.dll
      (verified)  Picasa                                   C:\Program Files\GooglePicasa3\npPicasa3.dll
      (verified)  Shockwave for Director                   C:\Windows\system32\Adobe\Director\np32dsw.dll
      (verified)  Silverlight Plug-In                      c:\Program Files\Microsoft Silverlight\4.0.50401.0\npctrl.dll
      (verified)  Système d'exploitation Microsoft® Windo  C:\Windows\system32\mswsock.dll
      (verified)  Système d'exploitation Microsoft® Windo  C:\Windows\system32\napinsp.dll
      (verified)  Système d'exploitation Microsoft® Windo  C:\Windows\system32\pnrpnsp.dll
      (verified)  Unity Player                             C:\Users\Cecile\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
      (verified)  Windows Presentation Foundation          c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
      (verified)  Windows® Internet Explorer               C:\Windows\system32\ieframe.dll


      Scan
      ----
      MD5: e68590c6931d93cfe35df7a26197b983  C:\Program Files\Crawler\Toolbar\ctbcomm.dll
      MD5: b55c22e1b3f605828c9188b5251c6230  C:\Program Files\Crawler\Toolbar\ctbr.dll
      MD5: 8072585704b83f53aa7b2575b2267b53  c:\Program Files\Crawler\Toolbar\WebSecurityGuard.dll
      MD5: 71221415676eb426775cb410ce9e9832  C:\Program Files\FileZilla FTP Client\fzshellext.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin2.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin3.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin4.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin5.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin6.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Internet Explorer\plugins\npqtplugin7.dll
      MD5: fe957e471958ce98456d98a6122c54d2  c:\Program Files\Microsoft Silverlight\4.0.50401.0\agcore.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll
      MD5: 8751001da5d5d9c9c8134ffab5e98f4c  C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll
      MD5: 0aee5668eb59912f32ff245bfa72465f  C:\Program Files\QuickTime\QTTask.exe
      MD5: 480b8218cac947db5f32d126fae2bacd  C:\Program Files\Spyware Terminator\SpywareTerminatorUpdate.exe
      MD5: 9aab7ebc99c559be4a6eca19428b49e5  C:\Program Files\Spyware Terminator\TorentDll.dll
      MD5: abb32a44090b77890f785153e41218de  C:\Program Files\VideoLAN\VLC\npvlc.dll
      MD5: 8f05b0b868dad01371c06eb464f2e675  C:\Windows\assembly\NativeImages_v2.0.50727_32\Microsoft.VisualBas#\b67478ec034fdf811a748f1b6b5b1c95\Microsoft.VisualBasic.ni.dll
      MD5: ce45722a3393b63843de48f314cf6b3f  C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\b6632a8b2f276a8e31f5b0f6b2006cd1\mscorlib.ni.dll
      MD5: b46192d9a0cb3072cb604a7691003cff  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\53f949f4664bb316f9b7a00d73a6e290\PresentationCore.ni.dll
      MD5: 7aa5fdbddc4ed1810bda7ca55316bcc1  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\231b0b42eff55de5c7d7debe555c16b7\PresentationFramework.Aero.ni.dll
      MD5: d02a01478be27a74c017262dd28abd72  C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\94f892556ec9fa7a508fc9d214ceaedf\PresentationFramework.ni.dll
      MD5: 25bc19b5a84e52a6d669c874ed9a537c  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\40da9084d0863e07d7ce55953833b8b0\System.Configuration.ni.dll
      MD5: 3359bb9ac44545c734d79f23557a3c33  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\9e53d9921c4bb153f1ffbe1ae0e1b615\System.Data.ni.dll
      MD5: d709af78422f6f0ef09cd0b79cfe743f  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\367c4043efc2f32d843cb588b0dc97fc\System.Drawing.ni.dll
      MD5: a9bb8332bef887a0f4adc3c88cc35bfc  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\1363115565fff5a641243a48f396f107\System.Windows.Forms.ni.dll
      MD5: 28a295aa6abd45f4557b6c00d0f8c5b1  C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\c1c06a392871267db27f7cbc40e1c4fb\System.Xml.ni.dll
      MD5: 8c70a2b884ffbbae50bbd21fb962a846  C:\Windows\assembly\NativeImages_v2.0.50727_32\System\f9c36ea806e77872dce891c77b68fac3\System.ni.dll
      MD5: 3b308420e61d1d218c2d6d6915756487  C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\fd2c727bcef2e019eb96c1145f423701\WindowsBase.ni.dll


      No file uploaded.

      Scan finished - communication took 0 sec
      Total traffic - 0.00 MB sent, 0.13 KB recvd
      Scanned 774 files and modules - 3 seconds

      ==============================================================================





      I really hope the process is ok... but I doubt since I don't find the different steps you mentionned.
      I wonder the website evolved ?

      SuperDave

      • Malware Removal Specialist


      • Genius
      • Thanked: 1020
      • Certifications: List
      • Experience: Expert
      • OS: Windows 10
      Re: Trojan removal - Thx for your help
      « Reply #34 on: November 28, 2011, 04:53:02 PM »
      Quote
      Are you sure of these steps ? Because I don't have the same options/steps you describe ...
      This is an older speech and the instructions will be dependant upon your OS.
      If there are no other issues, we can do some cleanup.


      To uninstall ComboFix

      • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
      • In the field, type in ComboFix /uninstall


      (Note: Make sure there's a space between the word ComboFix and the forward-slash.)

      • Then, press Enter, or click OK.
      • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System Restore.
      If this doesn't remove ComboFix, please let me know.
      ************************************************
      Clean out your temporary internet files and temp files.

      Download TFC by OldTimer to your desktop.

      Double-click TFC.exe to run it.

      Note: If you are running on Vista, right-click on the file and choose Run As Administrator

      TFC will close all programs when run, so make sure you have saved all your work before you begin.

      * Click the Start button to begin the cleaning process.
      * Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
      * Please let TFC run uninterrupted until it is finished.

      Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
      ****************************************************
      Looking over your log it seems you don't have any evidence of a third party firewall.

      Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

      Remember only install ONE firewall

      1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
      2) Online Armor
      3) Agnitum Outpost
      4) PC Tools Firewall Plus

      If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
      *****************************************************
      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
      Safe Surfing!
      Windows 8 and Windows 10 dual boot with two SSD's

      cian31

        Topic Starter


        Rookie

        • Experience: Familiar
        • OS: Windows Vista
        Re: Trojan removal - Thx for your help
        « Reply #35 on: November 29, 2011, 01:55:34 AM »
        Thanks a lot for your help and your attention to my problem !

        SuperDave

        • Malware Removal Specialist


        • Genius
        • Thanked: 1020
        • Certifications: List
        • Experience: Expert
        • OS: Windows 10
        Re: Trojan removal - Thx for your help
        « Reply #36 on: November 29, 2011, 04:41:12 PM »
        You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.
        Windows 8 and Windows 10 dual boot with two SSD's