UNSOLVED

xelacity

updated

15 years ago

X

xelacity

7 Posts

0

33659

February 11th, 2012 15:00

How to remove it?

I was surfing a Chinese auction site and accidentally dl a software which had been detached by my anti-virus as trojan. I was removed it by my anti-virus software but then the shortcut icon of that trojan is still on my desktop.

I tried to right click it and wish to delete, but its show as the following picture:

I tried to move it directly into bin but its show as the following picture:

http://desmond.imageshack.us/Himg803/scaled.php?server=803&filename=bin.png&res=medium

  • Bugbatter

    4 Apprentice

    20487 Posts

    1058

    0

    Posted February 11th, 2012 16:00

    Hi xelacity,

    Welcome to Dell Community. Are you not able to right-click on the icon to delete the shortcut?

    Do you remember the name of the software that accidentally downloaded? That information might help us in researching how to remove all components of it.

    For now, please try Malwarebytes' Anti-Malware.

    Please download the FREE version of Malwarebytes Anti-Malware and save it to your desktop.
    Alternate link: Malwarebytes Anti-Malware

    • Make sure you are connected to the Internet.
    • Double-click on mbam-setup.exe to install the application.
    • When the installation begins, follow the prompts and do not make any changes to default settings.
    • When installation has finished, make sure you leave both of these checked:
      • Update Malwarebytes' Anti-Malware
      • Launch Malwarebytes' Anti-Malware
    • Then click Finish.

    MBAM will automatically start and you will be asked to update the program before performing a scan.

      • If an update is found, the program will automatically update itself.
      • Press the OK button to close that box and continue.
      • If you encounter any problems while downloading the updates,

    manually download them from here
    and just double-click on mbam-rules.exe to install.
    Alternatively, you can update through MBAM's interface from a clean computer,
    copy the definitions (rules.ref) located in
    C:\Documents and Settings\All Users\Application Data\Malwarebytes\Malwarebytes'
    Anti-Malware from that system to a usb stick or CD and then copy it to the infected machine.

    On the Scanner tab:

      • Make sure the "Perform Quick Scan" option is selected.
      • Then click on the Scan button.
      • If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
      • The scan will begin and "Scan in progress" will show at the top.
      It may take some time to complete so please be patient.
      • When the scan is finished, a message box will say "The scan completed successfully.

    Click 'Show Results' to display all objects found

    • Click OK to close the message box and continue with the removal process.

    Back at the main Scanner screen:

    • Click on the Show Results button to see a list of any malware that was found.
    • Make sure that everything is checked, and click Remove Selected.
    • When removal is completed, a log report will open in Notepad.
    • The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
    • Copy and paste the contents of that report into your next reply and exit MBAM.

    Note:-- If MBAM encounters a file that is difficult to remove,
    you may be asked to reboot your computer so it can proceed with the disinfection process.
    Regardless if prompted to restart the computer or not, please do so immediately.
    Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware.

    -- MBAM may make changes to your registry as part of its disinfection routine.
    If you're using other security programs that detect registry changes (like Spybot's Teatimer),
    they may interfere with the fix or alert you after scanning with MBAM.
    Please disable such programs until disinfection is complete or permit them to allow the changes.

    **If you need to re-install MBAM but encounter issue in re-installing, try using the MBAM Cleanup Utility by downloading it from HERE

  • xelacity

    7 Posts

    1058

    0

    Posted February 11th, 2012 21:00

    Below are what I found from the scan... However, the icon still remind on my desktop and not able to be deleted. :(

    Malwarebytes Anti-Malware 1.60.1.1000
    www.malwarebytes.org

    Database version: v2012.02.12.01

    Windows Vista Service Pack 2 x86 NTFS
    Internet Explorer 9.0.8112.16421
    alexwe_cy :: SERVER [administrator]

    12/2/2012 10:12:57 AM
    mbam-log-2012-02-12 (10-12-57).txt

    Scan type: Full scan
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
    Scan options disabled: P2P
    Objects scanned: 433593
    Time elapsed: 2 hour(s), 56 minute(s), 26 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 9
    HKCR\AppID\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{1DD31B76-C57E-49ba-94BC-BF53F0C82CD4} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\CLSID\{91878E42-FC03-4785-B513-1F9E613D1027} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\TypeLib\{D02E3AB9-7796-40cb-BDFC-20D834FE1F75} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\Interface\{FCB380C4-D350-44BE-8791-50216F4747AC} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\ASBarBroker.BDBroker.1 (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\ASBarBroker.BDBroker (Adware.Funshion) -> Quarantined and deleted successfully.
    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{11CC93E4-0BE6-4f8f-82AA-D577FB955B05} (Adware.Funshion) -> Quarantined and deleted successfully.
    HKCR\AppID\activex.DLL (Adware.180Solutions) -> Quarantined and deleted successfully.

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 2
    C:\Users\alexwe_cy\AppData\Roaming\JjlDownLoader (Rogue.Installer) -> Quarantined and deleted successfully.
    C:\Users\alexwe_cy\Favorites\常用 (Malware.Trace) -> Quarantined and deleted successfully.

    Files Detected: 5
    C:\Users\alexwe_cy\Favorites\常用\淘宝商城 - 品牌正品 商城保障.url (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\alexwe_cy\Favorites\常用\淘宝女人频道-淘宝最权威的女装风向标!.url (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\alexwe_cy\Favorites\常用\淘宝男人频道-淘宝网最新潮流,前线导购,最全面的男人资讯.url (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\alexwe_cy\Favorites\常用\淘宝皇冠店铺大全.url (Malware.Trace) -> Quarantined and deleted successfully.
    C:\Users\alexwe_cy\Favorites\常用\淘宝网特卖频道 - 每日低价商品抢购中!.url (Malware.Trace) -> Quarantined and deleted successfully.

    (end)

  • Bugbatter

    4 Apprentice

    20487 Posts

    1058

    0

    Posted February 12th, 2012 04:00

    It looks as if MBAM found some more. There are probably some remnants left in there that may need to be removed with more powerful tools or manually.

    My suggestion is to post in the Malware Removal Forum at SpywareHammer and have the staff trained in malware removal walk you through the diagnostic logs and a cleanup. Help is free, but you will need to register there. In addition, there are other options listed at the top of the this forum. Some are free; some require a fee. Please use only one resource. It can be counter-productive to have too many people trying to help. Good luck! :emotion-1:

  • xelacity

    7 Posts

    1058

    0

    Posted February 12th, 2012 05:00

    Thank you so much Bugbatter for your suggestion. But the SpywareHammer link seem not working -.-"

  • Bugbatter

    4 Apprentice

    20487 Posts

    1058

    0

    Posted February 12th, 2012 05:00

    It's working for me. Try the link in my signature. Let me know if that works, so that I can quickly approve your registration there and get you in line for help.

    If that does not work it will take me an hour or two to make an adjustment to your access.

  • xelacity

    7 Posts

    1057

    0

    Posted February 12th, 2012 06:00

    Dear Bugbatter,

    I am testing ur link in both google chrome and IE, oso with url: http://spywarehammer.com/ . But both returned me with "Fedora Test Page".

  • Bugbatter

    4 Apprentice

    20487 Posts

    1057

    0

    Posted February 12th, 2012 06:00

    Thank you for letting me know. I will work on it and get back to you as soon as possible.

  • Bugbatter

    4 Apprentice

    20487 Posts

    1057

    0

    Posted February 12th, 2012 13:00

    Thank you for your suggestion, Rick, but everything is under control. We have been working on the server.

  • PudgyOne

    11 Legend

    30315 Posts

    106638 Points

    1057

    0

    Posted February 12th, 2012 13:00

    The links to Spyware Hammer work for me.

     

    Try this link. A SpywareHammer.com - Index

     

     

    Rick

  • Bugbatter

    4 Apprentice

    20487 Posts

    400

    0

    Posted February 12th, 2012 14:00

    xelacity, if you still cannot access SpywareHammer, it may take us until February 15 until we get the problem fixed.

    If you want your desktop icon issue handled sooner, please register at SpywareInfo Forums and follow the instructions for posting there. The help is free. Tell them Bugbatter sent you, and include the link to this topic at Dell Community.

    Please post back here and let me know what you decide to do -- wait a few days for SpywareHammer, or post at SpywareInfo Forums now.