Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Reinfection - trojan?  (Read 13885 times)

0 Members and 1 Guest are viewing this topic.

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #15 on: December 19, 2011, 01:30:55 PM »
Please run another scan with ESET and post  the log.
Windows 8 and Windows 10 dual boot with two SSD's

cgeorge107

    Topic Starter


    Rookie

  • Computer: Specs
  • Experience: Familiar
  • OS: Windows XP
Re: Reinfection - trojan?
« Reply #16 on: December 23, 2011, 04:24:58 PM »
So my MBR log looks clean.  You think it's clean now?

Thanks!
Cheryl

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #17 on: December 23, 2011, 04:30:22 PM »
Please run another scan with ESET and post the log.
Windows 8 and Windows 10 dual boot with two SSD's

cgeorge107

    Topic Starter


    Rookie

  • Computer: Specs
  • Experience: Familiar
  • OS: Windows XP
Re: Reinfection - trojan?
« Reply #18 on: December 27, 2011, 06:42:06 PM »
Eset Online Scan Log

# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1c2907bcb99ffc47978930e3b00e4d9c
# end=finished
# remove_checked=true
# archives_checked=false
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-28 12:51:57
# local_time=2011-12-27 07:51:57 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 27478837 27478837 0 0
# compatibility_mode=1024 16777191 100 0 1923570 1923570 0 0
# compatibility_mode=3073 16777213 80 71 2517196 6098000 0 0
# compatibility_mode=8192 67108863 100 0 26110793 26110793 0 0
# scanned=125935
# found=0
# cleaned=0
# scan_time=4336

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #19 on: December 27, 2011, 07:20:44 PM »
That looks good. If there are no other issues, we can do some cleanup.

* Click START then RUN - Vista users press the Windows Key and the R keys together for the Run box.
* Now type CherylCGF /uninstall in the runbox
* Make sure there's a space between CherylCGF and /Uninstall
* Then hit Enter

* The above procedure will:
* Delete the following:
* ComboFix and its associated files and folders.
* Reset the clock settings.
* Hide file extensions, if required.
* Hide System/Hidden files, if required.
* Set a new, clean Restore Point.
********************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***************************************************
Update Your Java (JRE)

Old versions of Java have vulnerabilities that malware can use to infect your system.


First Verify your Java Version

If there are any other version(s) installed then update now.

Get the new version (if needed)

If your version is out of date install the newest version of the Sun Java Runtime Environment.

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close ALL open web browsers before starting the installation.

Remove any old versions

1. Download JavaRa and unzip the file to your Desktop.
2. Open JavaRA.exe and choose Remove Older Versions
3. Once complete exit JavaRA.

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and reboot your computer.
************************************************
Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!
Windows 8 and Windows 10 dual boot with two SSD's

cgeorge107

    Topic Starter


    Rookie

  • Computer: Specs
  • Experience: Familiar
  • OS: Windows XP
Re: Reinfection - trojan?
« Reply #20 on: December 28, 2011, 06:09:06 PM »
Dave, I forgot to check the box to scan archive files so I ran it once more and the scan found 4 threats that it cleaned. I'm not sure if it was due to that box not being checked first time, but here is my log... I won't do anything else until I hear from you.

esets_scanner_update returned -1 esets_gle=53251
# version=7
# iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339)
# OnlineScanner.ocx=1.0.0.6583
# api_version=3.0.2
# EOSSerial=1c2907bcb99ffc47978930e3b00e4d9c
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-12-28 03:43:26
# local_time=2011-12-27 10:43:26 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 27487328 27487328 0 0
# compatibility_mode=1024 16777191 100 0 1932061 1932061 0 0
# compatibility_mode=3073 16777213 80 71 2525687 6106491 0 0
# compatibility_mode=8192 67108863 100 0 26119284 26119284 0 0
# scanned=126060
# found=4
# cleaned=4
# scan_time=6135
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\0\63562ec0-72ddb669   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\45\1494686d-5e79ac2d   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\47\6cde0e2f-315653e3   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C
C:\Documents and Settings\NetworkService\Application Data\Sun\Java\Deployment\cache\6.0\55\5db226b7-1d40eb03   multiple threats (deleted - quarantined)   00000000000000000000000000000000   C

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #21 on: December 28, 2011, 07:14:48 PM »
Ok. Please follow the clean-up instructions I posted and we'll be done.
Windows 8 and Windows 10 dual boot with two SSD's

cgeorge107

    Topic Starter


    Rookie

  • Computer: Specs
  • Experience: Familiar
  • OS: Windows XP
Re: Reinfection - trojan?
« Reply #22 on: December 29, 2011, 07:32:24 PM »
I keep getting the message, "Windows cannot locate file, CherylCGF". Make sure you are typing the name in correctly (something to that effect).

I'm typing it in correctly, have tried repeatedly. Have the space right, even copied and pasted from your instructions to make sure.  Can't figure it out.

???

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #23 on: December 29, 2011, 07:40:05 PM »
Quote
I'm typing it in correctly, have tried repeatedly. Have the space right, even copied and pasted from your instructions to make sure.  Can't figure it out.

Ok. I figured that it wouldn't work. Please do this.

Download this program and run it Uninstall ComboFix .It will remove ComboFix for you

********************************************
To set a new Restore Point.

Click Start button , click Control Panel, click System and Maintenance, and then clicking System. In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation. To turn off System Protection for a hard disk, clear the check box next to the disk, and then click OK. Reboot to Normal Mode.
Click the Start button , click Control Panel, click System and Maintenance, and then click System.
In the left pane, click System Protection.  If you are prompted for an administrator password or confirmation, type the password or provide confirmation.
To turn on System Protection for a hard disk, select the check box next to the disk, and then click OK.
This will give you a new, clean Restore Point.
Windows 8 and Windows 10 dual boot with two SSD's

cgeorge107

    Topic Starter


    Rookie

  • Computer: Specs
  • Experience: Familiar
  • OS: Windows XP
Re: Reinfection - trojan?
« Reply #24 on: December 31, 2011, 06:05:00 PM »
Completed all. Downloaded the ComboFix uninstall program and ran, popup box said "Done!".  Exe files still on desktop - is that okay?  Qoobox folder and BackEnv folders were removed by the 'uninstall program'.

I'm comfortable doing a manual removal if necessary.  Other than that, computer is running great!

Thanks for your help!

Cheryl

SuperDave

  • Malware Removal Specialist


  • Genius
  • Thanked: 1020
  • Certifications: List
  • Experience: Expert
  • OS: Windows 10
Re: Reinfection - trojan?
« Reply #25 on: December 31, 2011, 06:45:44 PM »
Completed all. Downloaded the ComboFix uninstall program and ran, popup box said "Done!".  Exe files still on desktop - is that okay?  Qoobox folder and BackEnv folders were removed by the 'uninstall program'.

I'm comfortable doing a manual removal if necessary.  Other than that, computer is running great!

Thanks for your help!

Cheryl
Hi Cheryl. You may manually remove them. You're welcome. I will lock this thread. If you need it re-opened, please send me a pm. Happy New Year
Windows 8 and Windows 10 dual boot with two SSD's