Thread: Win32.Reson
View Single Post
Old 10-07-2007, 01:33 PM   #4 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,605
OS: 2000 Pro; XP Pro; XP Home


Re: Win32.Reson

Do you recognize this as something you've intentionally installed?

C:\Program Files\ElmejorAntivirus

Open notepad and copy/paste the text in the quotebox below into it:

Quote:
http://www.techsupportforum.com/security-center/hijackthis-log-help/186139-win32-reson-post1112144.html#post1112144

DirLook::
C:\UGA6PY
C:\Documents and Settings\ANA\Application Data\ElmejorAntivirus
C:\Program Files\ElmejorAntivirus
C:\Documents and Settings\All Users\Application Data\TEMP

Suspect::[28]
C:\WINDOWS\system32\atl71.dll
Save this as CFScript.txt




Refering to the picture above, drag CFScript.txt into ComboFix.exe

When finished, it shall produce a log for you, C:\ComboFix.txt. Post that log in your next reply.

Note:
Do not mouseclick combofix's window whilst it's running. That may cause it to stall


When CF finishes running, the ComboFix log will open along with a message box--do not be alarmed. With the above script, ComboFix will capture a file to submit for analysis.

Ensure you are connected to the internet and click OK. A browser will open. Simply follow the instructions to copy/paste/send the requested file.



---------------------------------------------------------------------------------------------

Also, please do this:

Create an uninstall list:
  • Open HiJackThis
  • Click on the button " Open the Misc Tools section"
  • Click on the Box that says "Open Uninstall Manager"
  • Click on the button "Save list"
  • Copy and past the List from the notepad file into your post
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline