We're not done with this yet.
Computer on for much of the day and nothing, then about 5 my OH saw a threat come up, but before he could do anything it had disappeared. It didn't show in the virus vault. Ran a scan of C drive and two threats in usual two places. Had a thorough search of the computer and anything to do with the GPS was deleted, all there was were some logs of journeys made using the GPS (terrible English hope it's not what you teach!) Rebooted computer ran scan again, nothing. Also ran scan in safe mode, nothing.
In the last half an hour have had 4 threats all in C:\Documents and Settings|All Users\Documents\setup.exe none in GPS details. Yet.
Rosalind
No, one time I was opening a game of Solitaire (sad I know) but I've tried several times and it's only happened once.
Was copying a sudoku off a site I have used many times over the past couple of years without problems.
Web browsing has been limited to main stream sites such as Amazon, hotmail, and some UK ones which are well used. I don't use MSN even though it is installed.
I don't download music or videos.
Typed C:\Documents and Settings\All Users\Documents\setup.exe into "run" and got the reponse
Windows cannot access the specified device, path or file. You may not have the appropriate permissions to access the item. When I did this I got a threat warning, which I healed
Tried again and got Windows cannot find 'C:\documents' . Make sure you typed the name correctly and then try again. To search for a file, click the start button, and then click search.
Did this, in search got a brief glimse of the file, and then the threat, which I healed, nothing in the search then.
Rosalind
At the main screen of KillBox, select the option: Delete on Reboot
Then, in the Full Path of File to Delete box copy/paste the following entry:
C:\Documents and Settings\All Users\Documents\setup.exe
Press the button with a red circle and a white X (Delete File button)
KillBox will alert you: All listed files will be deleted on next Reboot
Click Yes
Next prompt will be: Files will be removed on reboot. Do you want to reboot now?
Select Yes
If your computer does not restart automatically, please restart it manually
"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Went fine until the press delete file button, then got:-
Pending File Rename Operations Registry Data has been Removed by External Process.
Presume it means it is sitting in the Virus Vault.
Rosalind
Except that it has supposedly healed/deleted Trojan horse Proxy.24.D 8 times
I looked in the object details, and where it says healable - NO
So why does AVG tell me that it has been successfully healed, now getting confused.
So why does AVG tell me that it has been successfully healed,
My guess is something else is installing it.
Lets make sure this one is gone as well
double-click on the killbox.exe program.
At the main screen of KillBox, select the option: Delete on Reboot
Then, in the Full Path of File to Delete box copy/paste the following entry:
C:\My Documents\GPS\Details\Setup.exe
Press the button with a red circle and a white X (Delete File button)
KillBox will alert you: All listed files will be deleted on next Reboot
Click Yes
Next prompt will be: Files will be removed on reboot. Do you want to reboot now?
Select Yes
If your computer does not restart automatically, please restart it manually
"copy/paste" a new log file into this thread.
Also please describe how your computer behaves at the moment.
Same response as previously. Not had another threat with the path GPS details, after I managed to find some other folders with GPS logs in and deleted them.
Prior to that I had another threat, same letters/numbers says it is successfully healed, but it is not. What would happen if I ignored the next one and then ran killbox?