Options

Is the trojan gone??

I didn't realize I had a trojan until my internet server suspended my internet account, in which case I ran Malwarebytes and Symantec and found a trojan and was quarantined easily. It seemed too simple for the internet provider to act so drastically. Can you help take a look at my logs to make sure it's completely gone? Thank you very much...

Comments

  • edited February 2009
    Hello. :)

    Logs look good to me, but just to be sure....

    Download: CCleaner (freeware)
    http://www.majorgeeks.com/download4191.html
    Run the installer, and uncheck the option to install Yahoo toolbar (unless you want Yahoo toolbar).
    Once installed, run CCleaner click the Windows [tab]
    The following should be selected by default, if not, please select:
    CCleanerA.png
    Then click Run Cleaner (bottom right) then Exit


    Next, please go HERE to run Panda ActiveScan 2.0
    • Click the big green Scan now button
    • If it wants to install an ActiveX component allow it
    • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
    • Once the scan is completed, please hit the notepad icon next to the text Export to:
    • Save it to a convenient location such as your Desktop
    • Post the contents of the ActiveScan.txt in your next reply
    .
  • edited February 2009
    Thanks for taking a look. Did as you said... Panda scan says the computer's infected... hope it's nothing bad. Here's the log.
  • edited February 2009
    1. Please download The Avenger by Swandog46 to your Desktop.
    [*]Right click on the Avenger.zip folder and select "Extract All..."
    [*]Follow the prompts and extract the avenger folder to your Desktop

    2. Copy all the text contained in the Quote box below to your Clipboard by highlighting it and pressing (Ctrl+C):
    Registry keys to delete:
    hkey_classes_root\vbrad.trayicon

    Files to delete:
    C:\Documents and Settings\Lucia\My Documents\Lucia\Applications, programs, BLAH\keygen.exe
    C:\Documents and Settings\Lucia\My Documents\Lucia\Applications, programs, BLAH\Stardock.WindowBlinds.Enhanced.v6.0.Incl.Keyfilemaker.And.Patch-EMBRACE\embrace.rar

    Note: the above code was created specifically for this user. If you are not this user, do NOT follow these directions as they could damage the workings of your system.


    3. Now, open The Avenger folder and start The Avenger program by clicking on its icon.
    • Right click on the window under Input script here:, and select Paste.
    • You can also Paste the text copied to the clipboard into this window by pressing (Ctrl+V).
    • Click on Execute
    • Answer "Yes" twice when prompted.
    4. The Avenger will automatically do the following:
    • It will Restart your computer. ( In cases where the code to execute contains "Drivers to Delete", The Avenger will actually restart your system twice.)
    • On reboot, it will briefly open a black command window on your desktop, this is normal.
    • After the restart, it creates a log file that should open with the results of Avenger’s actions. This log file will be located at C:\avenger.txt
    • The Avenger will also have backed up all the files, etc., that you asked it to delete, and will have zipped them and moved the zip archives to C:\avenger\backup.zip.
    5. Please copy/paste the content of c:\avenger.txt into your reply along with a fresh Panda ActiveScan log by using Add/Reply.
  • edited February 2009
    Panda's still not coming clean-- it's worse than before it seems.
  • edited February 2009
    Actually the rest are harmless...we just have to get rid of that registry entry now.

    Please run Notepad and paste the following text into a new file:
    REGEDIT4

    [-hkey_classes_root\vbrad.trayicon]

    Save the file to the desktop as fix.reg and make sure the "Save as Type" field says "All Files". Then please go to the desktop and double-click on fix.reg, and click Yes to merge it with the registry.

    Now restart your computer, and run one more scan with Panda. I'll keep my fingers crossed this time! :)
  • edited February 2009
    Thanks for helping me out so far, but hmm... no luck it seems.
  • edited February 2009
    I have no idea why you said no luck, because all the malicious entries in the log have been removed.

    You can run CCleaner again to remove those cookies. Next, navigate to and delete the following file becauase we have no more need of SmitfraudFix:
    C:\Documents and Settings\Lucia\My Documents\Lucia\Applications, programs, BLAH\SmitfraudFix.exe

    And also this folder:
    C:\Documents and Settings\Lucia\My Documents\Lucia\Applications, programs, BLAH\SmitfraudFix\


    You should be all fine. Are you having any more problems with your PC?
  • edited February 2009
    Oh cool. It seemed like the same number of viruses. Excellent, ran ccleaner.

    The computer's still being slow and weird every once in a while, but on the whole, it's fine. Just wanted to run it by an expert. Thanks for all your help.
  • edited February 2009
    Glad we could be of assistance! The help you received here was free.

    This topic is now closed. If you wish it reopened, please send a Private Message to Trogan with a link to your thread.

    If you are not the user who started this thread, you must start your own Thread instead :)
    _______________________________

    Have we helped you with any issues you have had with your PCs or other items? If so, you can now help us by Joining Team 93 and fold for a cure.
Sign In or Register to comment.