Avatar of thenelson
thenelson

asked on 

Unable to get rid of Trojans in Windows 7

HitmanPro displays several Trojans (see list below) and states they were deleted after reboot but they come back after a couple hours. I sent an email to HitmanPro about this and got a response to start hitman while holding down the left control key. I did this but it did not help. I downloaded and ran Super Anti-spyware. It stated it found and deleted several malwares but Hitmanpro still comes up with a list of Trojans. I am using Bitdefender Total Security 2017 as my antivirus. A complete scan with that turns up nothing.

Some symptoms that I am experiencing since the Trojans started showing up are I get a pop-up that states "failed to connect to a Windows service" when I reboot and Windows Aero is disabled when I reboot until I manually restart the Themes service in services.msc.

Here is a log from Hitmanpro:
HitmanPro 3.7.18.284
www.hitmanpro.com

   Computer name . . . . : LATITUDE_E6410
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Latitude_E6410\Nelson
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Paid (873 days left)

   Scan date . . . . . . : 2017-04-03 04:13:18
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 10m 16s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 14
   Traces  . . . . . . . : 14

   Objects scanned . . . : 2,031,243
   Files scanned . . . . : 106,370
   Remnants scanned  . . : 509,754 files / 1,415,119 keys

Malware remnants ____________________________________________________________

   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)

Any suggestions will be greatly appreciated.
Anti-SpywareWindows 7Security

Avatar of undefined
Last Comment
Shaun Vermaak

8/22/2022 - Mon