Virtumonde not removed

Do you recognize these?

C:\Documents and Settings\Tony\My Documents\Work\APF Pers\APF Barc 1-19
C:\Documents and Settings\Tony\My Documents\Work\APF Pers\ctimer.exe
 
Recognise or not

Shaba
Barc definitely recorgnised - 1 xls and the other a zip file. ctimer not sure but it is an archive file so not used for many years. I've deleted it and emptied recycle.
Thanks
Tony
 
Good :)

Empty this folder as well:

C:\Documents and Settings\All Users\Application Data\Symantec\Norton AntiVirus\Quarantine\

Empty Recycle Bin.

Please download ATF Cleaner by Atribune and save
it to desktop.

Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.

If you use Firefox browser

Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser

Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit to close ATF-Cleaner.

Still problems?
 
Clear - I think

ShabaI
Apologies for not replying sooner. I think I'm all clear now but had a strange error message on shut down for a couple of days "The instruction at ..... could not be read" or something similar. It didn't wait for me to OK but shut down anyway. Aplication was hpqgpc.exe and there was also 0x774fdf1b mentioned.

Many thanks for all your help and donation on its way.
Fabes
 
Try to manually kill all processes except antivirus and firewall before shutdown using task manager and let me know if it helped.
 
Shut down normal

Shaba
I normally shut all apps before shutting down anyway but it is now going through fine. Many many thanks for all your help.
 
Spoke too soon.

Shaba
The only app I sometimes leave open is Solitaire and on closing down with it open I got the error message again "The instruction at 0x774fdf1b referenced memory could not be read". Now doing other test to see if it happens with other apps open.
 
Since this issue appears to be resolved ... this Topic has been closed. Glad I could help.

Note: If it has been four days or more since your last post, and the helper assisting you posted a response to that post to which you did not reply, your topic will not be reopened. At that point, if you still require help, please start a new topic and include a fresh HijackThis log and a link to your previous thread.

If it has been less than four days since your last response and you need the thread re-opened, please send me or your helper a private message (pm). A valid, working link to the closed topic is required. Please do not add any logs that might have been requested in the closed topic, you would be starting fresh.
 
Back
Top