![]() |
![]() |
![]() |
|||||
![]() |
![]() |
![]() |
![]() |
![]() |
|||
| Welcome
to Tech Support Forum home to more then 136,000 problems solved. Issues
have included: Spyware, Malware, Virus Issues, Windows, Microsoft,
Linux, Networking, Security, Hardware, and Gaming Getting your
problem solved is as easy as: 1. Registering for a free account 2. Asking your question 3. Receiving an answer Registered members: * See fewer ads. * And much more..
|
| Want to know how to post a question? click here | Having problems with spyware and pop-ups? First Steps |
|
|||||||
| Resolved HJT Threads Resolved spyware and popup issues. |
|
|
Thread Tools |
|
|
#1 (permalink) |
|
Registered User
Join Date: May 2007
Posts: 7
OS: Windows xp
|
Help! Can't remove a trojan!
My computer got infected with a trojan "Exploit-ANIfile.c". I have McAfee anti-virus program and it kept warning me that the computer is infected with this trojan but that it can't be removed. When I run a scan, it didn't even recognize the trojan. So what do I do? How do I get rid of it? So far it's not a trouble, but I've read about it - other harmful viruses could get attached to it.
Please, if anyone have a suggestion, let me know. Thanks! |
|
|
|
|
#2 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Hi Ribica and welcome to TSF
Sorry for the delay in getting to you, the forum has been really busy lately and all our helpers are volunteers. If you still need help please follow these instructions For XP,2000 or Vista Download Deckard's System Scanner to your Desktop. Note: You must be logged onto an account with administrator privileges.
To attach a file to a new post, simply
What DSS will do:
------------------------------------------ For 95, 98 or ME Download HijackThis to your desktop
|
|
|
|
|
#3 (permalink) |
|
Registered User
Join Date: May 2007
Posts: 7
OS: Windows xp
|
Re: Help! Can't remove a trojan!
Ok, I did like you advised me to. What can you tell from it? Thanks.
Deckard's System Scanner v20070426.43 Run by Jelena on 2007-05-12 at 19 27Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- Successfully created a Deckard's System Scanner Restore Point. -- Last 5 Restore Point(s) -- 61: 2007-05-12 17 33 UTC - RP61 - Deckard's System Scanner Restore Point60: 2007-05-12 15:16:36 UTC - RP60 - System Checkpoint 59: 2007-05-10 19:48:48 UTC - RP59 - Software Distribution Service 2.0 58: 2007-05-10 14:45:41 UTC - RP58 - System Checkpoint 57: 2007-05-08 18:55:17 UTC - RP57 - System Checkpoint -- First Restore Point -- 1: 2007-02-28 20:25:11 UTC - RP1 - System Checkpoint Backed up registry hives. Performed disk cleanup. -- HijackThis (run as Jelena.exe) ---------------------------------------------- Logfile of HijackThis v1.99.1 Scan saved at 19:07:49, on 12.5.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\WgaTray.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\RunDll32.exe C:\WINDOWS\system32\igfxtray.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Program Files\McAfee.com\VSO\mcvsshld.exe C:\Program Files\McAfee.com\VSO\oasclnt.exe c:\program files\mcafee.com\agent\mcagent.exe c:\progra~1\mcafee.com\vso\mcvsescn.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe C:\Program Files\Messenger\msmsgs.exe c:\program files\mcafee.com\agent\mcdetect.exe c:\PROGRA~1\mcafee.com\vso\mcshield.exe c:\progra~1\mcafee.com\vso\mcvsftsn.exe c:\PROGRA~1\mcafee.com\agent\mctskshd.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\slserv.exe C:\Documents and Settings\Jelena\Desktop\Anti virus\dss.exe C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\HIJACK~1\Jelena.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.tportal.hr/ R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://us.mcafee.com/apps/vso/en-us/...sp?affid=439-1 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = MAXadsl Internet Explorer R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: McAfee VirusScan - {BA52B914-B692-46c4-B683-905236F6F655} - c:\progra~1\mcafee.com\vso\mcvsshl.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32 O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [VSOCheckTask] "C:\PROGRA~1\McAfee.com\VSO\mcmnhdlr.exe" /checktask O4 - HKLM\..\Run: [VirusScan Online] C:\Program Files\McAfee.com\VSO\mcvsshld.exe O4 - HKLM\..\Run: [OASClnt] C:\Program Files\McAfee.com\VSO\oasclnt.exe O4 - HKLM\..\Run: [MCAgentExe] c:\PROGRA~1\mcafee.com\agent\mcagent.exe O4 - HKLM\..\Run: [MCUpdateExe] c:\PROGRA~1\mcafee.com\agent\mcupdate.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVD.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - Startup: Stardock ObjectDock.lnk = C:\Program Files\Stardock\ObjectDock\ObjectDock.exe O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra button: T-Com - {821556D3-11A2-48D9-84A5-B9C71270049D} - C:\Program Files\Internet Explorer\SIGNUP\HTnet Start.exe (file missing) (HKCU) O12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dll O14 - IERESET.INF: START_PAGE_URL=http://www.tportal.hr/ O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/actives...ree/asinst.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{62DCEEB2-D1E1-4CE0-AA8F-5C45DFA58676}: NameServer = 195.29.150.3 195.29.150.4 O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: McAfee WSC Integration (McDetect.exe) - McAfee, Inc - c:\program files\mcafee.com\agent\mcdetect.exe O23 - Service: McAfee.com McShield (McShield) - McAfee Inc. - c:\PROGRA~1\mcafee.com\vso\mcshield.exe O23 - Service: McAfee Task Scheduler (McTskshd.exe) - McAfee, Inc - c:\PROGRA~1\mcafee.com\agent\mctskshd.exe O23 - Service: McAfee SecurityCenter Update Manager (mcupdmgr.exe) - McAfee, Inc - C:\PROGRA~1\McAfee.com\Agent\mcupdmgr.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe -- File Associations ----------------------------------------------------------- All associations okay. -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 RecAgent - c:\windows\system32\drivers\recagent.sys <Not Verified; ; Modem> R2 ElbyCDIO (ElbyCDIO Driver) - c:\windows\system32\drivers\elbycdio.sys <Not Verified; Elaborate Bytes AG; CDRTools> R3 AnyDVD - c:\windows\system32\drivers\anydvd.sys <Not Verified; SlySoft, Inc.; AnyDVD> R3 RMSPPPOE (WAN Miniport (PPP over Ethernet Protocol)) - c:\windows\system32\drivers\rmspppoe.sys <Not Verified; Robert Schlabbach; PPP over Ethernet Protocol> S3 Mtlmnt5 - c:\windows\system32\drivers\mtlmnt5.sys <Not Verified; ; Modem> S3 Mtlstrm - c:\windows\system32\drivers\mtlstrm.sys <Not Verified; ; Modem> S3 Slntamr (Generic AMR_PCI Driver) - c:\windows\system32\drivers\slntamr.sys <Not Verified; ; Modem> S3 SlNtHal - c:\windows\system32\drivers\slnthal.sys <Not Verified; ; Modem> S3 SlWdmSup - c:\windows\system32\drivers\slwdmsup.sys <Not Verified; ; Modem> -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 SLService (SmartLinkService) - slserv.exe <Not Verified; ; Modem> -- Files created between 2007-04-12 and 2007-05-12 ----------------------------- 2007-05-01 19:22:05 0 d-a------ C:\Documents and Settings\All Users\Application Data\TEMP 2007-05-01 19:21:44 0 d-------- C:\Program Files\Hotgames.com 2007-05-01 16:58:49 0 d-------- C:\WINDOWS\system32\ActiveScan 2007-05-01 14:49:42 0 d-------- C:\Documents and Settings\Jelena\Application Data\Help 2007-04-27 20:32:08 40296 --a------ C:\Documents and Settings\Jelena\Application Data\GDIPFONTCACHEV1.DAT 2007-04-12 15:25:02 0 d-------- C:\Documents and Settings\All Users\Application Data\Google 2007-04-12 15:24:25 0 d-------- C:\Program Files\Google 2007-04-12 15:02:56 0 d-------- C:\Documents and Settings\All Users\Application Data\Windows Genuine Advantage -- Find3M Report --------------------------------------------------------------- 2007-05-12 16:04:08 40 ---hs---- C:\Documents and Settings\Jelena\Application Data\.zreglib 2007-05-06 15:53:10 0 d-------- C:\Program Files\Messenger 2007-04-12 15:24:31 0 d-------- C:\Documents and Settings\Jelena\Application Data\Macromedia 2007-03-28 20:51:28 0 d-------- C:\Program Files\Ubisoft 2007-03-28 20:44:15 0 d--h----- C:\Program Files\InstallShield Installation Information 2007-03-26 17:17:09 0 d-------- C:\Documents and Settings\Jelena\Application Data\CyberLink 2007-03-15 23:15:00 0 d--h----- C:\Documents and Settings\Jelena\Application Data\Move Networks 2007-03-01 06:03:44 62 --ahs---- C:\Documents and Settings\Jelena\Application Data\desktop.ini 2007-02-28 22:19:41 0 -rahs---- C:\MSDOS.SYS 2007-02-28 22:19:41 0 -rahs---- C:\IO.SYS 2007-02-28 22:19:41 0 --a------ C:\CONFIG.SYS 2007-02-28 22:19:41 0 --a------ C:\AUTOEXEC.BAT 2007-02-28 22:16:25 21640 --a------ C:\WINDOWS\system32\emptyregdb.dat -- Registry Dump --------------------------------------------------------------- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects] {02478D38-C3F9-4EFB-9B51-7695ECA05670} C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx {53707962-6F74-2D53-2644-206D7942484F} C:\Program Files\Spybot - Search & Destroy\SDHelper.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "IMJPMIG8.1"="\"C:\\WINDOWS\\IME\\imjp8_1\\IMJPMIG.EXE\" /Spoil /RemAdvDef /Migration32" "PHIME2002ASync"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /SYNC" "PHIME2002A"="C:\\WINDOWS\\system32\\IME\\TINTLGNT\\TINTSETP.EXE /IMEName" "Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd" "igfxtray"="C:\\WINDOWS\\system32\\igfxtray.exe" "igfxhkcmd"="C:\\WINDOWS\\system32\\hkcmd.exe" "igfxpers"="C:\\WINDOWS\\system32\\igfxpers.exe" "VSOCheckTask"="\"C:\\PROGRA~1\\McAfee.com\\VSO\\mcmnhdlr.exe\" /checktask" "VirusScan Online"="C:\\Program Files\\McAfee.com\\VSO\\mcvsshld.exe" "OASClnt"="C:\\Program Files\\McAfee.com\\VSO\\oasclnt.exe" "MCAgentExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcagent.exe" "MCUpdateExe"="c:\\PROGRA~1\\mcafee.com\\agent\\mcupdate.exe" "NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "AnyDVD"="C:\\Program Files\\SlySoft\\AnyDVD\\AnyDVD.exe" "MSMSGS"="\"C:\\Program Files\\Messenger\\msmsgs.exe\" /background" [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\CTFMON.EXE" HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa Authentication Packages REG_MULTI_SZ msv1_0\0\0 Security Packages REG_MULTI_SZ kerberos\0msv1_0\0schannel\0wdigest\0\0 Notification Packages REG_MULTI_SZ scecli\0\0 [HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost] HTTPFilter REG_MULTI_SZ HTTPFilter\0\0 LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0 NetworkService REG_MULTI_SZ DnsCache\0\0 DcomLaunch REG_MULTI_SZ DcomLaunch\0TermService\0\0 rpcss REG_MULTI_SZ RpcSs\0\0 imgsvc REG_MULTI_SZ StiSvc\0\0 termsvcs REG_MULTI_SZ TermService\0\0 -- End of Deckard's System Scanner: finished at 2007-05-12 at 19:08:22 --------- |
|
|
|
|
#4 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Hi Ribica
I don't see any evidence of it in your logs, we can run through a general cleanup see if it shows up. Before we do your McAfee anti-virus appears to be disabled please re-activate McAfee. ------------------------------------------------------- Please print out or copy this page to Notepad in order to assist you while carrying out the following instructions. This page will not be available to you at some points during the fix. Please read the instructions carefully before you begin and if you have any questions then post them here before continuing. This process is not instant and may take several posts. Please ensure you continue with the instructions until you are told you are clear. Lack of symptons does not mean lack of malware. Please make sure you close all other windows including browsers when carrying out the fix. It is important you carry out the instructions in the exact order stated. ------------------------------------------------------- Downloads Please download ATF Cleaner by Atribune. (We will use this later) This program is for XP and Windows 2000 only Download AVG Anti Spyware Use the link at the bottom of the page under "AVG Anti-Spyware Free for Windows" ![]()
------------------------------------------------------- Show Hidden Files/Folders Go to My Computer >Tools >Folder Options >View tab and select Show hidden files and folders. Uncheck the Hide protected operating system files (recommended) option. Also make sure there is no checkmark beside Hide file extensions for known file types. Click OK. ------------------------------------------------------- Safe Mode Boot to Safe Mode (by repeatedly tapping F8 until the menu appears) ------------------------------------------------------- Tools and Scanners
For Technical Support, double-click the e-mail address located at the bottom of each menu. Run AVG Anti-Spyware with it's updated definitions:(...it's important that all windows must be closed)
------------------------------------------------------- Normal Mode Reboot to Normal Mode ------------------------------------------------------- Online Scan Perform an online scan with Internet Explorer with Panda ActiveScan
![]()
* Turn off the real time scanner of any existing antivirus program while performing the online scan ------------------------------------------------------- 1. Download combofix to your desktop from 1 of these locations http://download.bleepingcomputer.com/sUBs/ComboFix.exe http://www.techsupportforum.com/sect...s/ComboFix.exe 2. Double click combofix.exe & follow the prompts. 3. When finished, it shall produce a log for you. Post that log in your next reply Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall ------------------------------------------------------- Required Logs AVG AntiSpyware report Panda report C:\combofix.txt new HijackThis log |
|
|
|
|
#6 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Hi Ribica
I don't see Firefox or Opera in your uninstall list, you can verify this by Clicking Start>All Programs and check they are not there. If they are not then you can continue by doing just the first part of the ATF instructions Double-click ATF-Cleaner.exe to run the program. Under Main choose: Select All Click the Empty Selected button. Skip the Firefox and Opera part and continue with AVG AntiSpyware. |
|
|
|
|
#7 (permalink) |
|
Registered User
Join Date: May 2007
Posts: 7
OS: Windows xp
|
Re: Help! Can't remove a trojan!
Hi again! I still didn't go on with the instructions you gave me, I will though. But frist I wanna tell you, I was checking my WinRAR archive and I found the files and folders that McAfee was alerting me about and which it couldn't recognize later whan I ran a scan. Those files cannot be deleted. They are stored in C:\Documents and Settings\Jelena\Local Settings\Temporary Internet Files\Content.IE5. Those are:
3QO3B9KP\st[1] 4RDF6MR5\blank[1].html BFLJZ5CW\ep.styles[1].css st[1] ENIZQTEZ\album[1].htm M5TIFYTO\blank[1].html st[1] CA1WWZXT.htm CAYZ8L6R.htm MX38HORE\album[1].htm st[1] index_ppexit_2[1].htm NCMZ91ER\browserhistory[1].html CAAN46P7.htm RV5F31CV\launch[1].rand=ojd468j1spuot The thing is, when I go directly to Temporary Iternet Files folder, the folder Content.IE5 is not there. But when I look into WinRAR archive, it shows its presense. And when I try to delete them, I can't, just like McAfee alerted me. What do you think? |
|
|
|
|
#8 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Hi Ribica
That's good news, at least we now know where they are. The contents of Content.IE5 are hidden as that is a system folder, the previous set of instructions should take care of those but if not we can delete them manually but we will need to see the required logs first. |
|
|
|
|
#9 (permalink) |
|
Registered User
Join Date: May 2007
Posts: 7
OS: Windows xp
|
Re: Help! Can't remove a trojan!
Hey, I can't launch AVG, I get this message: "64-Bit edition of Windows is not supported". What now? A friend of mine gave me Norton Anti-Virus. Is ti better than McAfee? Should I install it?
|
|
|
|
|
#10 (permalink) |
|
Registered User
Join Date: May 2007
Posts: 7
OS: Windows xp
|
Re: Help! Can't remove a trojan!
You know something? Those suspicious files are all gone. I couldn't ran an AVG scan but I still wanted to try to go thru other of your instructions, so I ran ATF cleaner in safe mode, and after that they were gone. Is it possible?
Anyway, thanks a lot for your patience. I'll probably be back when I run into another problem Still, I have one more question. Which anti-virus program would you recommend? I have McAfee installed plus Spybot-Search&Destroy and Ad-Aware SE Personal. Should I install something else? |
|
|
|
|
#11 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Hi Ribica
Sorry for the delay, AVG AntiSpyware won't run on 64bit nor will combofix should you return to those instructions. ATF Cleaner cleans out the temp folders including Content.IE5 As for Anti-Virus it is a matter of preference whether you chose McAfee or Norton although Norton does slow the system down. Make sure that you only have 1 Anti-virus installed as they can conflict with one another causing undesirable results. Kindly follow these simple steps in order to keep your computer clean and secure:
Update all these programs regularly. Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released. Follow this list and your potential for being infected again will reduce dramatically. Here are some additional utilities that will further enhance your safety.
To find out more information about how you got infected in the first place and some great guidelines to follow to prevent future infections you can read this article by Tony Klein After doing all these, your system will be optimised against future threats. It's okay to delete the Hijack This folder in a couple weeks if everything is working okay. Have a safe & happy computing day. ![]() Please respond to this thread one more time so we can mark this thread as resolved. |
|
|
|
|
#13 (permalink) |
|
Analyst, Security Team
Join Date: Nov 2005
Location: UK
Posts: 1,968
OS: xp
|
Re: Help! Can't remove a trojan!
Your very welcome. If you need this thread re-opened please pm me or one of the moderators
*This applies only to the thread starter. If you are not the thread starter please start a new thread. |
|
|