Forum Home
Press F1
 
Thread ID: 126545 2012-09-03 22:37:00 File Recover Virus NZHawk (4093) Press F1
Post ID Timestamp Content User
1298758 2012-09-04 00:31:00 MalwareBytes doesn't catch everything, sometimes its quite useless actually.

try running Spybot S&D, Super Antispyware, and HitmanPro ( all in safe Mode.)

One thing you can do is look at the log that Rkill made - it will only kill the process, it usually wont delete the file. Look at the location of the infection that Rkill says it killed, navigate to it, and delete it from there manually.
wainuitech (129)
1298759 2012-09-04 00:37:00 will do Nick - report back after completed NZHawk (4093)
1298760 2012-09-04 01:16:00 They also had ZoneAlarm Anti-Virus & Firewall
so I removed McAfee & am updating ZoneAlarm for a scan

will also look at the RKill log
NZHawk (4093)
1298761 2012-09-04 01:20:00 They also had ZoneAlarm Anti-Virus & Firewall
so I removed McAfee & am updating ZoneAlarm for a scan

will also look at the RKill log
Can't say I'd be relying on zonealarm to be honest. I'd get Microsoft Security Essentials (windows.microsoft.com) - its fast, good, and free :)
Nick G (16709)
1298762 2012-09-04 01:22:00 Just looked at the RKIll log and
NO processes to stop or kill!

ZoneAlarm did find a malware infection: trojan: W32.jorik.zbot...
NZHawk (4093)
1298763 2012-09-04 01:26:00 Its a start at least. Also, clear your temp files, all kind of nasties can reside in there. CCLeaner will remove temp files if you have it. Nick G (16709)
1298764 2012-09-04 01:30:00 Ok will run CCleaner
a 2nd run of ZoneAlarm was clean
will uninstall & install, update & scan with MSSE
NZHawk (4093)
1298765 2012-09-04 01:50:00 You may have to do this (www.lavasoft.com) Speedy Gonzales (78)
1298766 2012-09-04 02:05:00 thanks Speedy NZHawk (4093)
1298767 2012-09-04 05:28:00 Finished scan with MSSE detected & removed:
VirTool:Win32/Injector.gen!CM
Trojan::Win32/FakeSysdef

scanned with BitDefender on-line scan: clean

is there a more thorough scan that I can assure there is no remaining infections?
NZHawk (4093)
1 2 3