1.

Solve : Hijackthis 2?

Answer»

And here we have...

--Computer 2--



[recovering disk space -- attachment deleted by admin]Download Malwarebytes' Anti-Malware (MBAM)

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Update Malwarebytes' Anti-Malware
    • Launch Malwarebytes' Anti-Malware
    • Then click Finish.
    • If an update is found, it will download and install the latest VERSION.
    • Once the program has loaded, SELECT Perform quick scan, then click Scan.
    • When the scan is complete, click OK, then Show Results to view the results.
    • Be sure that everything is checked, and click Remove Selected.
    • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
    • The log is automatically saved by MBAM and can be viewed by CLICKING the Logs tab in MBAM.
    • Copy and Paste the entire report in your next reply.
    Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

    ----------

    Now run a new HJT scan and post the log.Here we go, MalwareBytes' Anti Malware.

    [recovering disk space -- attachment deleted by admin]I forgot to request a new HJT log also.Oh Darn, you did put it up there.....I just didn't see it.

    Now I'm going to have to wait till tomorrow to run it again. (door to the computer room is locked) No problem. I'm pretty sure the MyWebSearch was the only problems showing and MBAM took care of that quite well.Indeed. My brother claims to know nothing about it....Here we go.


    [recovering disk space -- attachment deleted by admin]Are you running Kaspersky firewall and Symantec AV?

    ----------

    Open HijackThis and select Do a system scan only.

    Place a check mark next to the following entries: (if there)

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)


    Important: Close all windows except for HijackThis and then click Fix checked.

    Exit HijackThis.

    ----------

    Your Java is out of date.

    Older versions have vulnerabilities that malicious sites can use to infect your system.

    Download JavaRa to your Desktop and unzip it to its own folder.

    • Run JavaRa.exe, pick the language of your choice and click Select. Then click Remove Older Versions.
    • Accept any prompts. A log will appear (JavaRa.log), please post the contents of this log on the forum.
    • Open JavaRa.exe again and select Search For Updates.
    • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.
    Quote
    Are you running Kaspersky firewall and Symantec AV?
    I don't think so..... Norton 360 was on here before Kaspersky.

    Also, when running JavaRa, it CRASHED part of the way through the removal process. I ran it again and it seemed fine.
    Log attached.



    [recovering disk space -- attachment deleted by admin]There are about 5 or 6 instances of Norton running in the log, mostly Services.

    To completely remove Norton/Symantec go to add remove programs and uninstall anything with Norton, Symantec or Live Update in the name.

    Download the Norton Removal Tool (SymNRT) to your Desktop.

    Once downloaded please close ALL open browsers, also save any work because this may require a restart.

    • Go to your desktop and double click on the removal tool and then click Setup.
    • Once open Click Next
    • Accept the license agreement and click Next
    • Type in the letters/numbers that you see into the text box then click Next.
    • Then click Next and the tool will start running.
    • Once finished restart the PC and run the tool again to ensure everything has been removed.
    Thanks Evil.

    Norton is a SNEAKY little thing....I know you don't need it but you still get the closing speech Well a condensed version anyway.

    Set a New Restore Point to prevent possible reinfection from an old one
    Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
    • Go to Start > Programs > Accessories > System Tools and click System Restore
    • Choose the radio button marked Create a Restore Point on the first screen then click Next Give the Restore Point a name then click Create.
    • The new restore point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Next go to Start > Run and type Cleanmgr
    • Click OK
    • Click the More Options Tab.
    • Click Clean Up in the System Restore section to remove all previous restore points except the newly created clean one.
    You can find instructions on how to enable and re-enable system restore here:

    Windows XP System Restore Guide or Windows Vista System Restore Guide
    .
    ----------

    Use the Secunia Software Inspector to check for out of date software.
    • Click Start Now
    • Check the box next to Enable thorough system inspection.
    • Click Start
    • Allow the scan to finish and scroll down to see if any updates are needed.
    • Update anything listed.
    .
    ----------

    Important: You Need to Update Windows and Internet Explorer regularly to protect your computer from the malware and other security threats that are on the Internet. Go to Microsoft Windows Update and get all critical updates.





    Will do

    Unfortunately my bro is on the computer again.....


    Discussion

    No Comment Found