Page 2 of 2

Re: Computer running after virus removal

Posted: Sat Mar 03, 2012 1:54 pm
by Essexboy
OK no problem on that driver I will get it another way and it is currently inactive

If you could run FSS I will check the registry out for your net and security settings

Re: Computer running after virus removal

Posted: Sun Mar 04, 2012 12:29 am
by robertgu
Essexboy wrote:OK no problem on that driver I will get it another way and it is currently inactive

If you could run FSS I will check the registry out for your net and security settings
Ok Essexboy, please view the attached fss log. Thanks
FSS.txt3-3-12.zip
(734 Bytes) Downloaded 1021 times

Re: Computer running after virus removal

Posted: Sun Mar 04, 2012 12:19 pm
by Essexboy
OK that looks good how is the system behaving now ?

Re: Computer running after virus removal

Posted: Sun Mar 04, 2012 1:33 pm
by robertgu
Essexboy wrote:OK that looks good how is the system behaving now ?
Essexboy, so far the computer running pretty smoothly right now, I'll wait and see if anything comes up and report back to you.

Once again thanks for the help

Re: Computer running after virus removal

Posted: Sun Mar 04, 2012 2:22 pm
by Essexboy
Just delete the FSS tool from the desktop, there are no installed files

Re: Computer running after virus removal

Posted: Wed Mar 07, 2012 10:41 pm
by Fred
Hi guys, do you want me to mark this topic as Solved?

Re: Computer running after virus removal

Posted: Wed Mar 07, 2012 10:50 pm
by Essexboy
If robertgu is happy then so am I 8-)

Re: Computer running after virus removal

Posted: Wed Mar 07, 2012 10:56 pm
by robertgu
Fred wrote:Hi guys, do you want me to mark this topic as Solved?
Fred, that ok with me, the only issue I'm having right now is this error code (trojanproxy:js/banker. k error code) that MSE is picking up as a threat.
computer still running aok. thanks guys

Re: Computer running after virus removal

Posted: Wed Mar 07, 2012 11:00 pm
by Fred
Does MSE say the location of the file?

Re: Computer running after virus removal

Posted: Thu Mar 08, 2012 12:57 am
by robertgu
Fred, when I get home I'll check to see if mse give me a location.thanks

Re: Computer running after virus removal

Posted: Thu Mar 08, 2012 3:34 am
by robertgu
robertgu wrote:Fred, when I get home I'll check to see if mse give me a location.thanks
Fred this what I see in the history log. thanks

Re: Computer running after virus removal

Posted: Thu Mar 08, 2012 10:18 am
by Fred
Thanks, Robert. Can you please host another UVK log? Here are the instructions:

Open UVK and click Scan and create log.

Click Start scan.

Wait until the scan ends. The results will be saved to a file named UVKlog.txt on the desktop. the file will automatically be opened with the Log analyzer.

Close the Log analyzer. Zip the UVKlog.txt file in your desktop and host the zip as an attachment.

Thanks.

Re: Computer running after virus removal

Posted: Thu Mar 08, 2012 11:21 am
by Fred
Hi Robert. I've just analyzed your previous log and found some things you should remove.

Please download the attached zip. It contains a UVK script. Extract it to your desktop and double-click it. UVK will be launched, and the contents of the script will be loaded. Uncheck Create restore point and check Empty temporary folders.

Remember to save all your work. The script will kill all non essential processes and reboot the computer in the end. Click Run/Fix listed.

The script may take a while to complete, because it will also defrag your drives. So, maybe you should have a cup of tea while it runs.

The computer will then reboot. Please verify if there are no more MSE trojan warnings, and the performance has increased.

You may then post the new log anyway.

Thanks.
RobertGu.zip
(587 Bytes) Downloaded 902 times

Re: Computer running after virus removal

Posted: Fri Mar 09, 2012 1:47 am
by robertgu
Fred wrote:Hi Robert. I've just analyzed your previous log and found some things you should remove.

Please download the attached zip. It contains a UVK script. Extract it to your desktop and double-click it. UVK will be launched, and the contents of the script will be loaded. Uncheck Create restore point and check Empty temporary folders.

Remember to save all your work. The script will kill all non essential processes and reboot the computer in the end. Click Run/Fix listed.

The script may take a while to complete, because it will also defrag your drives. So, maybe you should have a cup of tea while it runs.

The computer will then reboot. Please verify if there are no more MSE trojan warnings, and the performance has increased.

You may then post the new log anyway.

Thanks.
The attachment RobertGu.zip is no longer available
Hey Fred,
I was not able run the script that you provided for me, this is the error code I'm getting now. Line 7700 cfile:\programfiles\uvk\uvk_en.ex error subscript used with non-array variable.

Re: Computer running after virus removal

Posted: Fri Mar 09, 2012 10:29 am
by Fred
Sorry. It seems the Stop all non MS services feature had a bug. Don't know how I missed that one. I'll fix it today and release a new build.

We don't need to use it anyway, since the services we're going to delete are already stopped.

Thanks for the report. Here's your new script:
RobertGu.zip
(576 Bytes) Downloaded 898 times
Don't forget to save all your work before running it.

Re: Computer running after virus removal

Posted: Sat Mar 10, 2012 7:53 am
by robertgu
Fred wrote:Sorry. It seems the Stop all non MS services feature had a bug. Don't know how I missed that one. I'll fix it today and release a new build.

We don't need to use it anyway, since the services we're going to delete are already stopped.

Thanks for the report. Here's your new script:
The attachment RobertGu.zip is no longer available
Don't forget to save all your work before running it.

Fred, so far this error (Trojanproxy) is not poping up. I also provided you with the latest log

Re: Computer running after virus removal

Posted: Sat Mar 10, 2012 11:27 am
by Fred
Hi Robertgu, Thanks for the log.

It seems clean. Here's another script. This one will restore a system file missing (hidserv.dll) and cleanup some log files in your C: root.
RobertGu.zip
(606 Bytes) Downloaded 912 times
After you run this script, please go to the Scan and create log section, un-check Recent files, click the small text box under Custom to clear it, and paste the following code:

Code: Select all

<Reg>
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify
Please ensure that Recent files is un-checked and Custom is checked. Click Start scan. This log will take less time to generate because UVK will not search for the recent files. It will probably be our last log, since I think your system is clean now. Please zip and attach the log.

Thanks.

Re: Computer running after virus removal

Posted: Tue Mar 13, 2012 2:00 am
by robertgu
Fred, for the last two days I didn't get any trojanproxy:js/banker. k errors and the computer is running great. thanks

Re: Computer running after virus removal

Posted: Tue Mar 13, 2012 10:24 am
by Fred
Ok, Glad we could help. Topic solved.