Author Topic: help geting rid of Alureon K and Trojans  (Read 11218 times)

0 Members and 1 Guest are viewing this topic.

bobjcpa

  • Guest
Re: help geting rid of Alureon K and Trojans
« Reply #30 on: September 12, 2012, 01:57:55 PM »
here is add_Remove Programs .txt, ComboFix-quarantined-files.txt and FSS log attached

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: help geting rid of Alureon K and Trojans
« Reply #31 on: September 12, 2012, 05:05:47 PM »
Hi bobjcpa,



Yor java is out of date.

Open Control Panel > Add/Remove Programs and uninstall

J2SE Runtime Environment 5.0 Update 6


You can get the newest version from HERE.

  • Scroll down to Windows Offline
  • click to download the file
  • Double click the file you downloaded to install
  • Decline any additional installs that may be offered.
Next, Double click on OTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
Code: [Select]
:Reg

:Services
CWJHCEGXFW

:Files
c:\docume~1\BOBJON~1\LOCALS~1\Temp\CWJHCEGXFW.exe

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the  OTL fix log.

Next

You have this program installed, Malwarebytes' Anti-Malware (MBAM). Please update it and run a scan.

Open MBAM

  • Click the Update tab
  • Click Check for Updates
  • If an update is found, it will download and install the latest version.
  • The program will close to update and reopen.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process,if asked to restart the computer,please do so immediatly.


Next


*Note
It is recommended to disable onboard antivirus program and antispyware programs while performing scans so there are no conflicts and it will speed up scan time.
Please don't go surfing while your resident protection is disabled!
Once the scan is finished remember to re-enable your antivirus along with your antispyware programs.



Go here to run an online scannner from
ESET

(Note: You can use Internet Explorer or FireFox for this scan. If you use FireFox you will be asked to install an additional component. Please allow this.)

  • Tick the box next to YES, I accept the Terms of Use.
  • Click Start
  • When asked, allow the activex control to install
  • Disable your Antivirus software. You can usually do this with its Notfication Tray icon near the clock
  • Click Start
  • Make sure that the option "Remove found threats" is Unchecked, and the option "Scan unwanted applications" is  Checked.
  • Click Scan.
  • Wait for the scan to finish.
  • When the scan completes, click List of found threats
  • click Export to Text file and save the file to your desktop using a unique name, such as ESETScan.
  • Include the contents of this report in your next reply
Note - when ESET doesn't find any threats, no report will be created.

  • Push the back button.
  • Push Finish
  • Re-enable your Antivirus software.
Please post back with
  • OTL log
  • MBAM log
  • ESET log if there was one
Any problems.

bobjcpa

  • Guest
Re: help geting rid of Alureon K and Trojans
« Reply #32 on: September 13, 2012, 05:45:50 AM »
attached are the otl and mbam logs.  NO threats were found when I ran ESET

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: help geting rid of Alureon K and Trojans
« Reply #33 on: September 13, 2012, 10:13:01 AM »
Hi bobjcpa,


Any problems? If not we'll clean up the tools.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • RogueKiller
  • TDSSKiller
I suggest you keep the xpUD disk, it may be handy some day.

From your flashdrive please delete
  • dumpit
  • MBR.zip
  • tdl_fix.sh
  • any other notepads we may have created

Next

Click the Start button, click Run. Copy and paste the following line into the run box and click OK

Combofix /uninstall


Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.


If you want to re-enable hibernate

Click start > Control Panel
  • Double-click Power Options
  • Click the Hibernate tab
  • check the 'Enable hibernate support'
  • click Apply, click ok
Reboot the computer.



Updates and upgrades

You have an older version of Adobe Reader.  You can download the current version HERE

You may want to consider Foxit Reader instead. It may be a bit lighter on resources. If you choose to use Foxit please decline the Foxit Toolbar.

Visit their support forum
Foxit Forum

In either case you should uninstall Adobe Reader 7.0.8 first. Be sure to move any PDF documents to another folder first though



Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware, IMO)


* You can install a Custom Hosts file with Spybot
1-Left-click the "Spybot - Search & Destroy" shortcut to open the program
2-Right-click an item in the list of immunizations and click "Deselect All."
3-Scroll down to the bottom of the list and click the checkbox to the left of "Global (Hosts)" under the "Windows" header.
4-Click "Immunize" on the Spybot toolbar.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.


- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis


- Make sure you have reset Automatic Updates to your chosen option. Click your start button > Control Panel > System > automatic Updates tab.


- Keep your antivirus program updated, as well as any other security programs you have.


-More tips and programs can be found HERE

 Please post back if you have any problems.

Take care

bobjcpa

  • Guest
Re: help geting rid of Alureon K and Trojans
« Reply #34 on: September 13, 2012, 01:38:35 PM »
Thanks for all your help and patience.  I never could have figured all this out without your help.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: help geting rid of Alureon K and Trojans
« Reply #35 on: September 13, 2012, 04:41:30 PM »
Hi bobjcpa,

No problem, you are welcome.