Author Topic: pls check for a virus/threat!  (Read 4206 times)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
pls check for a virus/threat!
« Reply #20 on: February 14, 2009, 11:46:46 PM »
Download [color=\"blue\"]OTMoveIt3.exe[/color] by OldTimer:
  • Save it to your desktop.
  • Right-Click on OTMoveit3.exe on desktop and select Run As Administrator
  • Copy the entries below in BLUE to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose "Copy"):

    ================================================

    [color=\"#0000FF\"]:Reg
    [-HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11c4bfbd-4b12-11dd-bcff-001e3d8820d6}][/color]



    ======================================================
  • Return to OTMoveIt3, right-click on the "Paste List of Files/Folders to be Moved" window  and choose "Paste".
  • Click the red "[color=\"red\"]MoveIt![/color]" button.
  • Close OTMoveIt when it has completed.
[color=\"red\"]Note[/color]:  If an entry cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose "Yes".

OTMoveIt would of created a log at this location
C:\_OTMoveIt\MovedFiles\mmddyyyy_hhmmss.log <-indicates date_time of log

Post that log please and let me know how things are now running
« Last Edit: February 14, 2009, 11:47:35 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline tanya

  • Jr. Member
  • **
  • Posts: 84
  • Karma: +0/-0
    • View Profile
pls check for a virus/threat!
« Reply #21 on: February 15, 2009, 04:05:00 PM »
Done...Here's the log:

========== REGISTRY ==========
Registry key HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{11c4bfbd-4b12-11dd-bcff-001e3d8820d6}\\ deleted successfully.
 
OTMoveIt3 by OldTimer - Version 1.0.8.0 log created on 02162009_010206

Things are working very well...haven't got any more virus alerts! Thank you for all your help http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> From your technical point of view is all ok?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
pls check for a virus/threat!
« Reply #22 on: February 16, 2009, 11:34:17 PM »
Go ahead and delete RSIT.exe from desktop, and it's folder it created
C:\rsit
Delete Flash_Disinfector from desktop

To remove ComboFix, bring up the Run box
Press the Windows Flag key and R  on your keyboard. . in the run box,
copy and paste the following

 [color=\"#FF0000\"]combofix /u[/color]
and press enter
This will uninstall ComboFix and it's components

OTMoveit3.exe
    Right-Click on OTMoveit3.exe on desktop and select Run As Administrator
    • Click the Cleanup! button
      A list will be downloaded>>Allow it Internet access if prompted by your Firewall
      Don't change anything in this list
    • Select Yes at the prompt
      Wait for the confirmation box to open to reboot the computer
      Don't mouseclick during the wait as you may cause the tool to stall
    • Select Yes to reboot Now
    NOTE: This procedure will also delete OTMoveit.exe from desktop

    Hold onto Malwarebyte's Anti-Malware and occassionally Update and run a Quick Scan
    You can delete everything from Quarantine

    Hope that helps  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

    Do you want to post your own logs from FRST?

    Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


    Offline tanya

    • Jr. Member
    • **
    • Posts: 84
    • Karma: +0/-0
      • View Profile
    pls check for a virus/threat!
    « Reply #23 on: February 27, 2009, 12:20:22 PM »
    Hi,

    Sorry for not having replied earlier...was traveling! Have removed all of the above...laptop is working beautifully for now http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' /> thank u very very much for all your help!

    Tanya

    Offline guestolo

    • Site Donator
    • Administrator
    • Hero Member
    • *****
    • Posts: 16034
    • Karma: +1/-0
      • View Profile
      • http://
    pls check for a virus/threat!
    « Reply #24 on: February 27, 2009, 06:53:19 PM »
    Thanks for posting back
    I'll lock this topic as your problems appear resolved
    Take care Tanya  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

    Do you want to post your own logs from FRST?

    Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here