1.

Solve : i need help with viruses?

Answer»

My Avg has detected a couple viruses can some one help me?
I loaded SUPERAntiSpyware and CCleaner i ran both but don't know what to do now
Please HelpPlease read post 1 an 2 in this thread then supply the logs.I have done all the steps
I run my AVG and keep getting C:\Documents and Settings\roger\Application Data\Yahoo!\Companion\Buttons\www.faceplace2002.com.ico & C:\Documents and Settings\roger\Application Data\Yahoo!\Companion\Buttons\www.whtmtnliving.net.ico
i have done everything i could think of to get rid of them , but nothing has worked, please help

[saving space - attachment deleted by admin]That is only one log when 3 were requested.

There are atleast two antivirus running on the computer. This is unnecessary and can cause problems. Uninstall one and keep the other.

----------

Open HijackThis and select Do a system scan only then place a check mark next to:


O2 - BHO: (no name) - {00000000-6CB0-410C-8C3D-8FA8D2011D0A} - (no file)
O2 - BHO: (no name) - {21B3F87D-304B-4B88-B58D-B3F493C9EFD7} - (no file)
O2 - BHO: (no name) - {51F51E05-1BB6-41B5-9D5C-51892CB9510e} - (no file)
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: (no name) - {8070445D-CFE0-4FB1-BE1D-525ED851D607} - (no file)
O2 - BHO: (no name) - {9ED6111B-2FB3-4CB9-BA2E-0C7EC3BEB43d} - (no file)
O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} -
O20 - Winlogon Notify: oppom - C:\WINDOWS\


Close all windows except for HijackThis and click Fix checked

----------

Please download DrWeb CureIt & save it to your desktop.

Scan with DrWeb-CureIt as follows:

  • Double-click on drweb-cureit.exe to start the program. An "Express Scan of your PC" notice will appear.
  • Under "Start the Express Scan Now", Click "OK" to start. This is a short scan that will scan the files currently running in memory and when something is found, click the Yes button when it asks you if you want to cure it.
  • Once the short scan has finished, Click Options > Change settings
  • Choose the "Scan tab" and UNcheck "Heuristic analysis"
  • Back at the main window, click "Select drives" (a red dot will show which drives have been CHOSEN)
  • Then click the "Start/Stop Scanning" button (green arrow on the right) and the scan will start.
  • When done, a message will be displayed at the bottom advising if any viruses were found.
  • Click "Yes to all" if it asks if you want to cure/move the file.
  • When the scan has finished, look if you can see the icon next to the files found. If so, click it, then click the next icon right below and select "Move incurable".
    (This will move it to the C:\Documents and Settings\userprofile\DoctorWeb\Quarantine folder if it can't be cured)
  • Next, in the Dr.Web CureIt menu on top, click file and choose save report list.
  • Save the DrWeb.csv report to your desktop.
  • Exit Dr.Web Cureit when done.
    • Important! Reboot your computer because it could be possible that files in use will be moved/deleted during reboot.
  • After reboot, post the contents of the log from Dr.Web in your next reply. (You can use Notepad to open the DrWeb.cvs report)
----------

Next post please attach
DrWeb log
New HijackThis log

it seems that in my last post i attached 3 logs but you said you only got 1 so i'm doing this in 2 post this time to make sure you get each attachment.
first one is drweb.csv log

[saving space - attachment deleted by admin]here is my log for hijackthis after my drweb scan log

[saving space - attachment deleted by admin]Open HijackThis and select Do a system scan only then place a check mark next to:

O16 - DPF: {8D7AFAB7-42D6-4671-A53E-CD355673F026} (SonySncMView Control) - http://65.196.226.166/SonySncMView.cab
O16 - DPF: {B64F4A7C-97C9-11DA-8BDE-F66BAD1E3F3A} - http://locator1.cdn.imagesrvr.com/sites/errorsafe.com/www/pages/scanner/ErrorSaf eNewReleaseInstall.cab


Close all windows except for HijackThis and click Fix checked


How is the computer running now?it seems to be doing good now... thank you!
after i'm done with everything what should I do with the stuff i loaded such as Drweb, hijackthis, CCleaner and superanti ?
is superanti better than AVG? You can keep them as they are free to use whenever you may need them.


To learn more about how to protect yourself while on the internet read this article by Tony Klien: So how did I get infected in the first place?


Let us know if ANYTHING else comes up.


Discussion

No Comment Found