Help, How to I get rid of these viruses???

  1. #1
    mjlopinto1 is offline Newbie

    Exclamation Help, How to I get rid of these viruses???

    I completed a BitDefender scan and these viruses were found. How do I delete them??



    Scanned File
    Status

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Infected with: JS.Trojan.Downloader.IstBar.M

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Disinfection failed

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Deleted

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ACF4520.dll=>(Quarantine-2)
    Infected with: Trojan.Downloader.Keenval.E

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ACF4520.dll=>(Quarantine-2)
    Disinfection failed

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\1ACF4520.dll=>(Quarantine-2)
    Deleted

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEF78FD.htm=>(Quarantine-2)
    Infected with: JS.Trojan.Downloader.IstBar.M

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEF78FD.htm=>(Quarantine-2)
    Disinfection failed

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEF78FD.htm=>(Quarantine-2)
    Deleted

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEF78FD.tmp=>(Quarantine-2)
    Infected with: Trojan.Downloader.IstBar.JA

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\6AEF78FD.tmp=>(Quarantine-2)
    Deleted

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0014
    Infected with: Trojan.Dloader.HK

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0014
    Disinfection failed

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0014
    Deleted

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe
    Update failed

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0015
    Infected with: Dropped:Application.Adware.NewDotNet.A

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0015
    Disinfection failed

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0015
    Deleted

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe
    Update failed

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0016
    Infected with: Trojan.Dropper.Small.JH

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0016
    Disinfection failed

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe=>wise0016
    Deleted

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe
    Update failed


  2. #2
    VopThis is offline Senior Member (Canada)
    Are you certain that the items of interest weren't properly addressed or deleted? Do you have any of those items that have returned? If they have, please post a HijackThis log that may help to identify reinfection agents, etc.

    Note that Bitdefender is quite verbose in its feedback - it normally takes 3 lines as follows to 1) list an infection item, 2) state whether disinfection or other action took place, and 3) state any alternate action that was taken as a last attempt such as item deletion and/or whether an updated clean version was obtainable (extractable from a ZIP file, for example):
    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Infected with: JS.Trojan.Downloader.IstBar.M

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Disinfection failed

    C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\0C6F6C78.htm=>(Quarantine-2)
    Deleted

  3. #3
    mjlopinto1 is offline Newbie
    They all keep coming up in scans.

    Quote Originally Posted by VopThis
    Are you certain that the items of interest weren't properly addressed or deleted? Do you have any of those items that have returned? If they have, please post a HijackThis log that may help to identify reinfection agents, etc.

    Note that Bitdefender is quite verbose in its feedback - it normally takes 3 lines as follows to 1) list an infection item, 2) state whether disinfection or other action took place, and 3) state any alternate action that was taken as a last attempt such as item deletion and/or whether an updated clean version was obtainable (extractable from a ZIP file, for example):

  4. #4
    VopThis is offline Senior Member (Canada)
    Save 20% on AVG Internet Security 2012 Suite!
    Clean out your Norton quarantine area.


    Run the following tool in SAFE MODE when requested below:

    Clean out TEMPORARY FILES:
    To clean your temp folder, recycle bin, etc..please download this free tool:

    CCleaner http://www.ccleaner.com/downloadbuilds.asp

    Install Options:
    • Don't install any Toolbars, or other programs, should it ask you!
    • Just uncheck the option of installing the Yahoo toolbar.

    It will put a shortcut on your Desktop.

    Select the ‘Cleaner’ BUTTON option (top LEFT), if not already selected. Use the ’Windows’ TAB up front by default.
    • Uncheck ‘Cookies’ option (advisable)
    • Optionally, Uncheck ‘Recently Typed URLs’ option (potentially still useful)
    • Click the ‘Analyse’ button.
    • Thereafter, click ‘Run Cleaner’ after you have reviewed what it proposes to clean.


    HIDDEN FILES: To make sure you can see all hidden files, please follow the directions here

    SAFEMODE: Boot into safe mode by tapping the F8 key at restart and choosing 'safe mode' menu option (explained here if needed).



    Run CCleaner, now.




    Navigate to these files or folders using Windows Explorer (OR Start -> Search) and delete (if present):


    DELETE FILES:

    C:\Documents and Settings\Owner\My Documents\Download\ffviitheme.exe




    POST A HIJACKTHIS LOG for review:
    See the following link for guidance, if needed:
    http://www.d-a-l.com/help/showthread.php?t=32403

    Reboot and post a HijackThis log with any feedback as appropriate - how things are now behaving: any new or remaining apparent issues.

+ Reply to Thread