Thread: Win32.Reson
View Single Post
Old 10-08-2007, 08:32 AM   #8 (permalink)
tetonbob
Manager, Security Center, TSF Academy; Analyst, Security Team
 
tetonbob's Avatar
 
Join Date: Jan 2005
Location: Transylvania County, North Carolina, USA
Posts: 35,158
OS: 2000 Pro; XP Pro; XP Home


Re: Win32.Reson

Thanks.

There does not appear to be an entry in Add or Remove Programs for the item in question. Since it's not a good idea to have more than one AntiVirus program installed, that's ok. I believe this to be part of a rogue application install.

To tidy up the system, I'd recommend you delete these folders:

C:\UGA6PY
C:\Documents and Settings\ANA\Application Data\ElmejorAntivirus
C:\Program Files\ElmejorAntivirus


And delete the contents of this folder(not the folder itself):

C:\Documents and Settings\All Users\Application Data\TEMP

Open HijackThis and click on 'Do a System Scan Only'. Check the following entries if they exist (make sure you do not miss any) and click Fix Checked

O22 - SharedTaskScheduler: beers - {b8ea5f37-7327-4923-9808-8fd3b6f0d529} - C:\WINDOWS\system32\ddllup.dll (file missing)

Close HijackThis now.

---------------------------------------------------------------------------------------------

Please download SmitfraudFix (by S!Ri) to your Desktop.

Double-click smitfraudfix.exe to start the tool.
Select option #1 - Search by typing 1 and press "Enter"
and a text file will appear which lists infected files (if present).
Please copy/paste the content of that report into your next reply.

IMPORTANT: Do NOT run option #2 OR any other option until you are directed to do so!

---------------------------------------------------------------------------------------------

Also post a new HijackThis log.

Do you know if Norton AntiVirus 2004 subscription is current?
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006

Microsoft MVP - Consumer Security 2009
tetonbob is offline