Author Topic: Yet another win32:tratBHO{Trj}  (Read 8494 times)

0 Members and 1 Guest are viewing this topic.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Yet another win32:tratBHO{Trj}
« Reply #15 on: February 14, 2008, 04:06:21 AM »
Hi
The part of the post you asked about, it's part of my copy/pasted canned version of the comboscript fix that didn't apply in this case. Must have missed it when I removed that part.

Well, it looks like we may have to hammer those two.

Any other problems?

Please download
 OTMoveIt2 by OldTimer.


Save it to your desktop.

Please double-click OTMoveIt2.exe to run it.


Copy the file paths below to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):


C:\WINDOWS\b116old.exe
C:\WINDOWS\b122old.exe


Return to OTMoveIt2, right click in the "Paste List of Files/Folders to be Moved" window (under the light blue bar) and choose Paste.

Click the red Moveit! button.

Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose copy), and paste it in your next reply.

Close OTMoveIt2

If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes.

NOTE: If OTMOVEITE reboots, before you can get the ruslts they can be found here
 C:\_OTMoveIt\MovedFiles\********_******.log
(where "********_******" is the "date_time")


Nodge

  • Guest
Re: Yet another win32:tratBHO{Trj}
« Reply #16 on: February 14, 2008, 12:25:54 PM »
OK. Done that and got this ...

C:\WINDOWS\b116old.exe moved successfully.
C:\WINDOWS\b122old.exe moved successfully.
 
OTMoveIt2 v1.0.20 log created on 02142008_112326



John

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Yet another win32:tratBHO{Trj}
« Reply #17 on: February 14, 2008, 02:34:49 PM »
That should have been the last of them.

Everything ok now? Let me know.

Here's a clean up routine to if eveything is good.

* Click start button, run, then copy and paste the following line into the box and click ok.

ComboFix /u


* Open OTMoveIt, then click the Clean Up button. You may get prompted by your firewall that OTMoveIt wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will delete all the tools you have downloaded plus itself.


* Make a new clean restore point

To clear existing restore points

1.Click Start, click All Programs, click Accessories, click System Tools, and then click System Restore.
 
2.Click to add a check mark beside Turn off System Restore on all Drives, and click Apply.
 
3. When you are warned that all existing Restore Points will be deleted, click Yes to continue.
 

All system restore points are deleted.

* Now you should manually create a restore point.

1.Click Start, click All Programs, click Accessories, click System Tools, and then click System Restore.
 
2.Click Create a Restore Point, and then click Next.
 
3.Name your restore point. (use the date as well as a descriptive term such as "After Restore Point Deletion.") click create, click close.
 
* Update your java

Open an Internet Explorer (only) window and go to http://java.sun.com/javase/downloads/index.jsp > Scroll down to "Java Runtime Environment (JRE) 6 Update 4...allows end-users to run Java applications".

Click the download button on the right.

 > If Information Bar pop-ups up, right-click on it and say it's OK to display the blocked content.

 You do not have to install the Java Web Start ActiveX Control


Accept the license agreement > Click on Windows (XP,Vista, .etc) Offline Installation, Multi-language and Save the file jre-6u4-windows-i586-p.exe to your desktop; do not Run it.

When the download is complete, Open Control Panel > Add/Remove Programs:

Uninstall anything that says Sun Java, Java JRE, or similar.

Close Add/Remove Programs.

In Windows Explorer, navigate to C:\Program Files\Java <=this folder, if found. Delete any subfolders it may contain.

Do NOT delete C:\Program Files\JavaVM <=this folder, if found!

Reboot your computer.

Double-click on the saved file to install the update.

Delete the downloaded installation file after completing the above procedure  and reboot if not prompted to do so.

* Download and run this clean up utility. You can use it regularly. When it's first run, it is in demo mode to show you what it will remove. Review it and then rerun in real mode. It is configurable.

CleanUp


* If you are using windows firewall, please note that it doesn't provide outbound protection. A third party firewall will.

A discussion on free firewalls can be found here.

http://forum.avast.com/index.php?topic=30808.0

Don't forget to re-enable Teatimer.

Take care abd keep safe.


Nodge

  • Guest
Re: Yet another win32:tratBHO{Trj}
« Reply #18 on: February 14, 2008, 04:22:20 PM »
OK. Working through that. About to remove the old Java stuff. I have the attached listed under Add/Remove Programs. Do I remove them all?

Thanks

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Yet another win32:tratBHO{Trj}
« Reply #19 on: February 14, 2008, 04:31:35 PM »
Yes, they are all old versions.

Nodge

  • Guest
Re: Yet another win32:tratBHO{Trj}
« Reply #20 on: February 14, 2008, 04:56:17 PM »
All done  :)

Many thanks for your help Oldman. All seems to be running ok. To be honest all I noticed before was Avast popping up with a virus warning. Just out of interest what were all these nasties doing to my system?

John

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Yet another win32:tratBHO{Trj}
« Reply #21 on: February 19, 2008, 02:50:16 PM »
Sorry, I didn't see your reply.

Most of it was vundo, and it was probably getting ready to download more of it's friends and swamp you in ad popups.

You're welcome.