Solved 8 steps of malware removal required

Status
Not open for further replies.
There is a folder named boot in c drive, should I delete it also?

please suggest an alternative for eset.

I wanted to know that y ccleaner is showing so many registry errors even after running TFC. some of mine softwares do not run, and their folders name are presnt in registry errors list in ccleaner. can my softwares run if we correct these errors.

I ran hijackthis, but in its folder, no new log is coming. only the old 1 is present. when I started hijackthis, I was prompted an error. the screen shot I have posted below.
 

Attachments

  • Capture.JPG
    Capture.JPG
    84.5 KB · Views: 3
there is a folder named boot in c drive, should i delete it also?
No.

please suggest an alternative for eset.
Uninstall Eset first.
Download and install one of these:
- Avira free antivirus: http://www.free-av.com/en/download/1/avira_antivir_personal__free_antivirus.html
- Avast! free antivirus: http://www.avast.com/eng/download-avast-home.html

i wanted to know that y ccleaner is showing so many registry errors
Leave registry error alone for now.
Our goal is to make sure, your computer is clean. One thing at a time.

can my softwares run if we correct these errors
When your computer is declared clean, you'll create new topic in Windows forum about those issues and we'll go from there.

when i started hijackthis, i was prompted an error. the screen shot i have posted below
According to my instructions, when you run HJT on Vista, you have to right click on HJT icon and click "Run As Administrator".
Post fresh HJT log only AFTER you're done with sorting out your antivirus program status.
 
Broni

am sry for missing the " run as administrator " step. wont happen again!

in the hijackthis window there was an option, save log. so I saved the log and it is posted as attachement below.

as per ur last post, so should I 1st install an antivirus form ur links and then run hijackthis as administrator or this attached file should serve the purpose?
 

Attachments

  • hijackthis1.txt
    5.4 KB · Views: 3
As I said, uninstall Eset, install new AV and THEN give me fresh HJT log.
I need to see, Eset is gone and new AV program is running.
 
Broni

eset was not unistall from control panel(uninstall a program) so I had deleted many of its folders maually.

I installed avira AV and then ran hijackthis as administrator.

the log file generated is posted as attachment below

do I need to keep MALWARE BYTES softaware or can I unisntall it?
 

Attachments

  • hijackthis2.txt
    5.8 KB · Views: 3
Yes, keep Malwarebytes and run occasional scans. It's the best antimalware program, you can get.

=======================================================================

Print this post out, since you won't have an access to it, at some point.

1. Open HijackThis.

2. Close all windows, except for HijackThis.

3. Put checkmarks next to the following HijackThis entries (these are unnecessary startups; no actual programs will be removed):

O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [SigmatelSysTrayApp] %ProgramFiles%\SigmaTel\C-Major Audio\WDM\sttray.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background


5. Click on Fix checked button.

6. Restart computer.


When done...


Your computer is clean

1. Turn off System Restore:

- Windows XP:
1. Click Start.
2. Right-click the My Computer icon, and then click Properties.
3. Click the System Restore tab.
4. Check "Turn off System Restore".
5. Click Apply.
6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
7. Click OK.
- Windows Vista and 7:
1. Click Start.
2. Right-click the Computer icon, and then click Properties.
3. Click on System Protection under the Tasks column on the left side
4. Click on Continue on the "User Account Control" window that pops up
5. Under the System Protection tab, find Available Disks
6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C:")
7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
8. Click OK

2. Restart computer.

3. Turn System Restore on.

4. Make sure, Windows Updates are current.

5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

7. Run defrag at your convenience.

8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

9. Please, let me know, how is your computer doing.
 
hello broni...

sry i couldnt come earlier as my internet connection had stopped working. i just got it repaired yesteday.
hope u will find this post and i can re-establish the connection with u.

broni i read ur last post and will create a recovery point after updating the windows.
rest , i think my pc is working very gud.

i have some queries reagarding the software ccleaner, plz guide me how to move abt to solve them.

thx...
 
Broni

when I run ccleaner software for registry errors, many errors are found.
I am attaching the a screen shot of the software, where u can have a look at the boxes checked for errors.

I think becoz of there registry errors I am not able to run some softwares and y are these errors coming?
 

Attachments

  • ccleaner.jpg
    ccleaner.jpg
    194.6 KB · Views: 0
but TFC doesnt show the errors displayed by ccleaner?i am not gng to use any registry tool unless adviced by u...

and how to go about the softwares which do not work ?

what to do about the errors of shown by ccleaner of those softwares which i have removed from the system. ccleaner shows that there r files in the registry of those softwares which i have removed from the system. what to do about them?
 
Nothing. Leave registry totally alone. Those entries do NOT bother anything.
Did you read the link I provided?
 
yes i read it and for d same reasons i nvr clicked on " fix errors" button.

broni, i have eg to share.

there is a software "INTERNET DOWNLOAD MANAGER". i had downloaded this from net, and it was a demo version for which i tried to search a keygen but it dint work. i unistalled the software. now whenever, i downloaded anything , a window used to get opened asking for key of Internet download manager even though i had unistalled it.

i think this is because of registry error and thats y i ask.

if u still say that it is not a prob and i should remove ccleaner , then i wont press upon the issue.
 
Yes, in case of troubleshooting, the registry can be approached, but with extreme caution.
Create restore point first.
Run CCleaner registry part and make sure, you checkmark entries related to that download manager ONLY.

Keep me posted.
 
broni

i created a resotre point as stated in ur last post.

i then checked the errors of download manager and fixed them. it asked me to create a backup file which i saved on the desktop. then it asked me to delete the registy entry and fix the issue which i did.

can i do with other registry errors which i confirmly know that i have removed the softwares form my pc. eg- there is a software named ANSYS which i have deleted and there are many registry errors of it.,
another is leechget(download manager). another is folder lock, eset anithvirus,microsoft silverlight.
these are those softwares which i have removed from my pc, but there registry errors r comming in ccleaner.

should i fix them or leave them?
should i delete the backup file created during the fixing of INTERNET DOWNLOAD MANAGER error???
 
should i delete the backup file created during the fixing of INTERNET DOWNLOAD MANAGER error???
The best way is to keep it for a few days to see, if Windows doesn't complain about something.

As for other registry entries...
If you review them one-by-one and you're 150% sure they belong to some uninstalled programs, you should be OK removing those.
For the future, unless, you're getting some issues like with that download manager, leave registry alone.
 
Status
Not open for further replies.
Back