One of the bagle files is still showing in your HJT log.
Let's do this:
KillBox v2.0.0.175.exe (it's important that you get version v2.0.0.175)
Launch
KillBox.exe & select the following
options:
Select all the filenames below & then right-click & select Copy
- C:\WINNT\system32\winshost.exe
* Go to the File menu, and choose
Paste from Clipboard
* Click the
RED X button.
* Click Yes at the Delete on Reboot prompt.
* Click Yes at the 'Pending Operations prompt'.
Quote:
|
If you receive a message such as: "Component 'MsComCtl.ocx' or one of its dependencies not correctly registered: a file is missing or invalid." when trying to run TheKillbox, download and run missingfilesetup.exe. Then try Killbox again.
|
Reboot into safe mode.
Run a scan in HijackThis. Check each of the following and hit 'Fix checked' (after checking them) if they still exist (make sure not to miss any):
O4 - HKCU\..\Run: [winshost.exe] C:\WINNT\system32\winshost.exe
Run Killbox again, and run
C:\WINNT\system32\winshost.exe through it again. If Killbox tells you it can't find it, that's a good thing.
Reboot into normal mode now.
Restart and run a new HijackThis scan. Save the log file and post it here.
Perform an online scan with Internet Explorer with
Kaspersky WebScanner
Next Click on
Launch Kaspersky Anti-Virus Web Scanner
You will be prompted to install an ActiveX component from Kaspersky, Click
Yes.
- The program will launch and then begin downloading the latest definition files:
- Once the files have been downloaded click on NEXT
- Now click on Scan Settings
- In the scan settings make that the following are selected:
- Scan using the following Anti-Virus database:
- Scan Archives
Scan Mail Bases
- Click OK
- Now under select a target to scan:
- This will program will start and scan your system.
- The scan will take a while so be patient and let it run.
- Once the scan is complete it will display if your system has been infected.
- Now click on the Save as Text button:
- Save the file to your desktop.
- Copy and paste that information in your next post.
Take note the names and locations of any file it detects but fails to clean.
* Turn off the real time scanner of any existing antivirus program while performing the online scan
Post results from Kaspersky scan, and a new HJT log, please.
__________________
Practice Safe Surfing
Because what you don't know, CAN hurt you.
Proud Member of ASAP since 2005
Proud Member of UNITE since 2006