WiredWX Christian Hobby Weather Tools
Would you like to react to this message? Create an account in a few clicks or log in to continue.

WiredWX Christian Hobby Weather ToolsLog in

 


descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
Well, that explains why the autorun file didn't want to go away.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Bankerfox.A - Page 1 DXwU4
Bankerfox.A - Page 1 VvYDg

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
All right! I did as you said and rebooted. The bankerfox madness is gone and avast appears to run normal, however when I run a scan with my newly installed PC Tools Spyware Doctor I am told that I have 4 threads and 102 infections on my computer. But that might have been the case before and is not really a problem? In any case, it seems that I can work normally again and thank you dearly for all your help!

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
Lies. They are saying that to get you to buy their product, then when you buy it, no threats are found.

My recommendations? get rid of Spyware Doctor.

Please download and run this tool.

Download Malwarebytes' Anti-Malware from Here

Double Click mbam-setup.exe to install the application.

  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts.
Click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.


Post the contents of the MBAM Log.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Bankerfox.A - Page 1 DXwU4
Bankerfox.A - Page 1 VvYDg

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
Malwarebytes' Anti-Malware 1.44
Database version: 3693
Windows 6.0.6001 Service Pack 1
Internet Explorer 8.0.6001.18882

2/5/2010 12:19:25 PM
mbam-log-2010-02-05 (12-19-25).txt

Scan type: Quick Scan
Objects scanned: 103524
Time elapsed: 3 minute(s), 32 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\Software\avsoft (Trojan.FakeAV) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoActiveDesktopChanges (Hijack.DisplayProperties) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Users\Cornel\AppData\Local\Temp\ajosnu.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\Cornel\AppData\Local\Temp\sfkqci.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
Hello.

How is the machine running now?

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Bankerfox.A - Page 1 DXwU4
Bankerfox.A - Page 1 VvYDg

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
as good as new. Thank you for your help. This was a great experience!

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
Okay, this should be fine now.

To remove all of the tools we used and the files and folders they created do the following:
Double click OTL.exe.

  • Click the CleanUp! button.
  • Select Yes when the "Begin cleanup Process?" prompt appears.
  • If you are prompted to Reboot during the cleanup, select Yes.
  • The tool will delete itself once it finishes.

............................................................................................

Site Admin / Security Administrator

Virus Removal ~ OS Support ~ Have we helped you? Help us! ~ GeekChat
- Please PM me if I fail to respond within 24hrs.
Bankerfox.A - Page 1 DXwU4
Bankerfox.A - Page 1 VvYDg

descriptionBankerfox.A - Page 1 EmptyRe: Bankerfox.A

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum