Hi Vince,
It looks like Judy will be away for the week, so I'll try to keep an eye on your thread as best I can
Looks like some of the infected .exes were removed and therefore not detected by RenV. Can you tell me what they were?
Which Vundo tool? Atribune's VundoFix? I still see Vundo in the HJT Log...
Actually, I'd like you to disable the "Tea Timer" as it just gets in the way of fixes. Or, just disable Spybot for the time being.
Do you still have the log from AVG AV when those deletions were made? I'd like to see it.
-- You'll need to reinstall any damaged programs. Might be best to wait until After we finish, though
Let's go ahead and do this:
-- Look in Add/Remove programs and remove any old Java versions and then reinstall latest version.
http://www.java.com/en/
- Download combofix.exe by sUBs to the infested computer's Desktop.
- Alternate Download
- (If you already have a previous version, delete it and download a new version).
- Double click combofix.exe & follow the prompts.
Note: Combofix will automatically disconnect your Internet connection when it runs, do not reconnect it.
When it finishes, it ought to
- Produce a log for you. ( C:\Combofix.txt)
- Restore your Internet connection.
IMPORTANT:
- Do not use your computer while Combofix is running.
- Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
If you've lost your Internet connection when Combofix has completely finished, re-start your computer to restore it.
Please post the log for me and we'll go from there.
I will try to check back as time permits - I don't work with malware too often these days due to other commitments.
Cheers
PP






Reply With Quote