View Single Post
Old 06-12-2009, 02:57 PM   #4 (permalink)
CatByte
Analyst, Security Team
 
CatByte's Avatar
 
Join Date: Jan 2009
Location: Canada
Posts: 2,150
OS: XP sp3


Re: DDS does not support my operating system (Trojan removal help)

Hi.

Please do the following:

Start OTS
Copy/Paste the information inside the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Quote:
[Kill All Processes]
[Unregister Dlls]
[Registry - Safe List]
< Run [HKEY_USERS\S-1-5-21-1181517193-3524019295-1311160477-1000\] > -> HKEY_USERS\S-1-5-21-1181517193-3524019295-1311160477-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
YN -> "Cognac" -> C:\Users\Shontia\AppData\Local\Temp\b.exe [C:\Users\Shontia\AppData\Local\Temp\b.exe]
[Files/Folders - Created Within 30 Days]
NY -> {5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job -> C:\Windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
NY -> {783AF354-B514-42d6-970E-3E8BF0A5279C}.job -> C:\Windows\tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
[Files/Folders - Modified Within 30 Days]
NY -> 1 C:\Windows\*.tmp files -> C:\Windows\*.tmp
NY -> 2 C:\Users\Shontia\AppData\Local\Temp\*.tmp files -> C:\Users\Shontia\AppData\Local\Temp\*.tmp
NY -> 5 C:\Users\Shontia\AppData\Local\Temp\Low\*.tmp files -> C:\Users\Shontia\AppData\Local\Temp\Low\*.tmp
NY -> {5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job -> C:\Windows\tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
NY -> {783AF354-B514-42d6-970E-3E8BF0A5279C}.job -> C:\Windows\tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
NY -> a.dat -> C:\Users\Shontia\AppData\Local\Temp\a.dat
NY -> d.exe -> C:\Users\Shontia\AppData\Local\Temp\Low\d.exe
[File - Lop Check]
NY -> {5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job -> C:\Windows\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job
NY -> {783AF354-B514-42d6-970E-3E8BF0A5279C}.job -> C:\Windows\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job
[Purity]
[Empty Temp Folders]
[Start Explorer]
[Reboot]
The fix should only take a very short time. When the fix is completed a message box will popup either telling you that it is finished, or that a reboot is needed to complete the fix. If the fix is complete, click the Ok button and Notepad will open with a log of actions taken during the fix. Post that log back here in your next reply.

If a reboot is required, click the "Yes" button to reboot the machine. After the reboot, OTS will finish moving any files that could not be moved during the fix and NotePad will open with the final results at that time. Post that log back here in your next reply.


Also, please describe how your computer is running now and if there are any outstanding issues.
__________________


ASAP & UNITE Member
CatByte is offline