DO NOT use any TOOLS such as Combofix, SmitfraudFix, MBAM, Vundofix, or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Vista users: 1. These tools MUST be run from the executable. (.exe) every time you run them
2. With Admin Rights (Right click, choose "Run as Administrator")
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders." Uncheck "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All [external image: Posted Image]
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Hello LD. Below is the Malwarebytes' scan log. After running this program I did get a message which indicated to reboot in order to remove one of the trojan threats. After doing so I didn't get any AVG Resident Shield message indicating a threat. BTW…could you tell me how I can receive email notification when you respond? For some reason I did not receive an email notification when you responded the first time. Thanks for your help!
MALWAREBYTES LOG
Malwarebytes' Anti-Malware 1.41
Database version: 2775
Windows 5.1.2600 Service Pack 3
10/22/2009 8:28:05 AM
mbam-log-2009-10-22 (08-28-05).txt
Whether you wish to continue with cleaning or not, you should be aware that you may have been infected by a backdoor trojan. This type of program has the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.
Please post back to let me know how you wish to proceed.
Whether you wish to continue with cleaning or not, you should be aware that you may have been infected by a backdoor trojan. This type of program has the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
Consider what other private information could possibly have been taken from your computer and take appropriate steps
This infection can almost certainly be cleaned, but as the malware could be configured to run any program a remote attacker requires, it will be impossible to be 100% sure that the machine is clean, if this is unacceptable to you then you should consider reformatting the system partition and reinstalling Windows as this is the only 100% sure answer.
Please post back to let me know how you wish to proceed.
Thanks LD. Wow, that wasn't the answer I was hoping for. But I think to be on the safe side I will go ahead and reformat the hard drive. However, I just have two questions. 1) I have an excel file that is locked that has passwords for my clients for whom I manage money. Should I assume that these may have been pirated and change those too? 2) I'm assuming that all my other files (word, excel, etc) are not infected and I can safely back them up and reinstall them on the newly formatted drive? Thank you!
Hello LD. Well, this is interesting. There is no "logon.exe" file in my windows\system32 directory. Here are the only "logon'' files in that directory:
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance.
If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.
Everyone else please begin a New Topic.
✨ Ask AI
AI can make mistakes. Check the cited posts. Archived advice can be out-of-date
Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI