Your hijackthis log appears to be clean. We will take care of the infected files now.
Now please delete all the files in C:\avenger folder.
Empty your recycle bin.
Reset and Re-enable your System Restore to remove infected files that have been backed up by Windows. The files in System Restore are protected to prevent any programs changing those files. This is the only way to clean these files: (You will lose all previous restore points which are likely to be infected)
Turn off System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
Check Turn off System Restore.
Click Apply, and then click OK.
Reboot.
Turn ON System Restore.
On the Desktop, right-click My Computer.
Click Properties.
Click the System Restore tab.
UN-Check *Turn off System Restore*.
Click Apply, and then click OK.
Please run Kapersky again and post (reply) with the results. Let's see the progress!
Susan:
Kaspersky ran and searched 190,518 files with no infections and no questionable files found. It doesn't produce a report when the computer is deemed to "clean".
Thank you so very much, but now to my earlier question about anti-virus software. Do you think that NOD 32 is a good product, or would you prefer Kaspersky? I know that the reports I've seen rate both quite highly, but for this project, it may have been a combination of familiarity and some program options that caused you to choose Kaspersky.
My Firewall seesm to be frequently reporting an attack from "RPC DCOM" followed by an IP address, so I guess it's working.
Regards and again, thank you.
I will be making a donation to help with the costs of keeping the TomCoyote Forum alive and well.
I was surprised at the differences of results between NOD32 and Kapersky. I have been using ewido and Kapersky frequently with my replies. If you want to keep NOD32 for awhile, you might just run some online scans occasionally and see if anything else is detected.
Stay up to date on security patches and be extremely wary of clicking on links and attachments that arrive unbidden in instant messages and e-mail.
"The number one thing the majority of the malicious code we're seeing now does is disable or delete anti-virus and other security software," Dunham said. "In a lot of cases, once the user clicks on that attachment, it's already too late."
Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
Update your AntiVirus Software - It is imperative that you update your Antivirus software at least once a week (Even more if you wish). If you do not update your antivirus software then it will not be able to catch any of the new variants that may come out.
Test your Firewall - Please test your firewall and make sure it is working properly. Test Firewall
Visit Microsoft's Update Site Frequently - It is important that you visit Windows Updates regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
Install Spybot - Search and Destroy - Install and download Spybot - Search and Destroy with its TeaTimer option. This will provide realtime spyware & hijacker protection on your computer alongside your virus protection. You should also scan your computer with program on a regular basis just as you would an antivirus software.
A tutorial on installing & using this product can be found here: Using Spybot - Search & Destroy to remove Spyware , Malware, and Hijackers
Install Ad-Aware - Install and download Ad-Aware. ou should also scan your computer with program on a regular basis just as you would an antivirus software in conjunction with Spybot.
A tutorial on installing & using this product can be found here: Using Ad-aware to remove Spyware, Malware, & Hijackers from Your Computer
Install SpywareBlaster - SpywareBlaster will added a large list of programs and sites into your Internet Explorer settings that will protect you from running and downloading known malicious programs.
A tutorial on installing & using this product can be found here: Using SpywareBlaster to protect your computer from Spyware and Malware
Update your Java to the latest version. Uninstall any and all versions you have listed in add/remove programs and install the latest version from here:
https://sdlc6c.sun.com/ECom/EComActionServl…4E1EA2D176EE3EA
Update all these programs regularly - Make sure you update all the programs I have listed regularly. Without regular updates you WILL NOT be protected when new malicious programs are released.
Susan:
One final question; should I remove the avenger program from my computer (It appears to be only on my desktop.), now that its work appears to be done?
Regards.
Susan:
As you know, every situation should be a learning one. So I have this comment on your helpfulness. You were courteous and your instructions were generally clear. The one item that caused me a lot of grief was in not knowing that with Netscape, I had to compact the files before the programs you were using to detect malware and intrusions would not be able to find them. For the next person in a similar situation, I'd ask that you add that to your instructions, and perhaps there's a need to compact all files, along with cleaning out the temp files.
Again, thanks a lot and regards.
Hello M1ck3y,
I very sorry about the problem with the compacting folders and I appreciate your feedback. I will remember this the next time I encounter this situation again with infected email files.
Regards,
Susan
Glad we could be of assistance. This topic is now closed. If you wish it reopened, please send us an email (Click for address) with a link to your thread.
Do not bother contacting us if you are not the topic starter. A valid, working link to the closed topic is required along with the user name used. If the user name does not match the one in the thread linked, the email will be deleted.
Make sure you use proper prevention to keep from having problems occur to your computer in the future.