troubleshooting Question

Unable to get rid of Trojans in Windows 7

Avatar of thenelson
thenelson asked on
Anti-SpywareWindows 7Security
19 Comments4 Solutions588 ViewsLast Modified:
HitmanPro displays several Trojans (see list below) and states they were deleted after reboot but they come back after a couple hours. I sent an email to HitmanPro about this and got a response to start hitman while holding down the left control key. I did this but it did not help. I downloaded and ran Super Anti-spyware. It stated it found and deleted several malwares but Hitmanpro still comes up with a list of Trojans. I am using Bitdefender Total Security 2017 as my antivirus. A complete scan with that turns up nothing.

Some symptoms that I am experiencing since the Trojans started showing up are I get a pop-up that states "failed to connect to a Windows service" when I reboot and Windows Aero is disabled when I reboot until I manually restart the Themes service in services.msc.

Here is a log from Hitmanpro:
HitmanPro 3.7.18.284
www.hitmanpro.com

   Computer name . . . . : LATITUDE_E6410
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Latitude_E6410\Nelson
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Paid (873 days left)

   Scan date . . . . . . : 2017-04-03 04:13:18
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 10m 16s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No

   Threats . . . . . . . : 14
   Traces  . . . . . . . : 14

   Objects scanned . . . : 2,031,243
   Files scanned . . . . : 106,370
   Remnants scanned  . . : 509,754 files / 1,415,119 keys

Malware remnants ____________________________________________________________

   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\about.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvcl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\bdfvwiz.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\deloeminfs.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\driverctrl.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\odsw.exe\ (Trojan.FakeAV)
   HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\setloadorder.exe\ (Trojan.FakeAV)

Any suggestions will be greatly appreciated.
ASKER CERTIFIED SOLUTION
aravind anche
Windows/Vmware

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Join our community to see this answer!
Unlock 4 Answers and 19 Comments.
Start Free Trial
Learn from the best

Network and collaborate with thousands of CTOs, CISOs, and IT Pros rooting for you and your success.

Andrew Hancock - VMware vExpert
See if this solution works for you by signing up for a 7 day free trial.
Unlock 4 Answers and 19 Comments.
Try for 7 days

”The time we save is the biggest benefit of E-E to our team. What could take multiple guys 2 hours or more each to find is accessed in around 15 minutes on Experts Exchange.

-Mike Kapnisakis, Warner Bros