infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by duncan32, May 18, 2006.

  1. duncan32

    duncan32 Private E-2

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Delete this file C:\Documents and Settings\Josh Craver\Local Settings\Temp\VVSNInst.exe.

    You have both Norton Antivirus and AVG Free Edition installed. Never install more than 1 antivirus program on your computer. They will conflict with each other and cause performance issues as well. Pick one uninstall the other.
     
  3. duncan32

    duncan32 Private E-2

    Deleted Norton (thru add/delete programs) due to 90 day subscription running out. However, in deleting the file C:\Documents and Settings\Josh Craver\Local Settings\Temp\VVSNInst.exe., what is the best way to do this? I am in the administrator account vs my sons account. I am still learning how to do these things properly.

    Also, going thru the the Read and Run me first, it says to enable view of hidden system files. Do I leave these unhidden?
     
  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You can delete that file from either account, doesn't really mattter. You should leave it that way the entire time we are working on the computer. Afterwards you can leave it that way or change it back.

    Post a fresh HijackThis log.
     
  5. duncan32

    duncan32 Private E-2

    this has been really frustrating...under explorer...i have no access to any of his folders like I do everyone elses? It doesn't have the drop down options. How can I fix this so I can?
     
  6. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Download
    - Pocket Killbox

    Log into his account.

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (This file may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.
     
  7. duncan32

    duncan32 Private E-2

    ran thru Pocket Killbox, CCleaner, and Cleanmgr. Also ran a new HiJack This log as follows:
     

    Attached Files:

  8. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

  9. duncan32

    duncan32 Private E-2

    Thank you for all of your help!!! It has been a challenge but at the same time it is very interesting in learning all of this neat stuff!! Next challenge...my laptop.

    You guys are AWESOME!!!!
     
  10. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    You're Welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds