| Forum Home | ||||
| Press F1 | ||||
| Thread ID: 101380 | 2009-07-13 04:11:00 | It's hijacked | HotShotAB (15091) | Press F1 |
| Post ID | Timestamp | Content | User | ||
| 791320 | 2009-07-13 07:56:00 | Speedy.. Did what you told me. The AV09 stuff is still popping up. I uninstalled and reinstalled malwarbytes. Still will not install on the computer. I cannot scan it yet. I'll attach a new log so you can see. | HotShotAB (15091) | ||
| 791321 | 2009-07-13 07:57:00 | AV pro 2009 can be a real bugger to remove - Malwarebytes will get most of it, but not all (usually) you may have to manually check and remove any left overs. Once Malwarebytes has done its scan, run Spybot S&D, as well as super antispyware, you'll be surprised how many infections the whole lot combined remove ( Software Links from my sig) then have a look at This thread (www.bleepingcomputer.com) Scroll down the bottom, and check each one has been deleted - if they have not then it will reinfect. NOTE: ALWAYS do full scans - not quick scans. If I could just get malwarebytes to run... |
HotShotAB (15091) | ||
| 791322 | 2009-07-13 08:00:00 | www.imagef1.net.nz updated log... see if I missed anything. |
HotShotAB (15091) | ||
| 791323 | 2009-07-13 08:01:00 | Get teamviewer if you want and I'll check it out from here. So how did you uninstall it if it didnt install? Or since it was installed, why did you uninstall it (malwarebytes)? Since it was in add/remove programs. The startup entries look ok now | Speedy Gonzales (78) | ||
| 791324 | 2009-07-13 08:07:00 | Sorry, meant to say that it would install, but it will not run. Just sits idle after clicking on run. I also had to rename to get it to install. I'm dl'ing teamviewer right now | HotShotAB (15091) | ||
| 791325 | 2009-07-13 08:09:00 | Send me a pm with the ID and password, after you install it and run it. Better not put it in this post. | Speedy Gonzales (78) | ||
| 791326 | 2009-07-13 08:33:00 | Send me another PM Hotshot. Looks like trojan remover picked up a rootkit. UACD.sys. Whatever it was it was hiding. It also had this (www.sophos.com) It probably rebooted, as it d/c me | Speedy Gonzales (78) | ||
| 791327 | 2009-07-13 09:02:00 | Right think I fixed it bloody trojan and rootkit ! That bloody Mcenspc.dll, and brastk.exe file. Soon find out | Speedy Gonzales (78) | ||
| 791328 | 2009-07-13 09:29:00 | Alright... you got it to where I could run malwarebytes. It caught 46 more infected objects. I'm going to run it again now and see if it catches anymore. I just wanted to give you and update. I'll post the malwarebytes log if there aren't anymore infections. I can already tell that it's about 4 million times better though. Thank you, Speedy! |
HotShotAB (15091) | ||
| 791329 | 2009-07-13 09:31:00 | No worries, good to hear :) At least Malwarebytes is running ! I would install something like Avast Home (free) or NOD32, if you want to pay for something. And sure windows is up to date with updates. It probably didn't affect trojan remover, because that changes filenames. So nothing (hopefully) can stop it | Speedy Gonzales (78) | ||
| 1 2 3 4 5 6 | |||||