also @ TechSpot: Google, Samsung unveil Chromebook, Chromebox with Chrome OS 19

TechSpot

Error (login): 0x10... & memory allocation

Discussion in 'Virus and Malware Removal' started by LcB838, Dec 12, 2009.

Thread Status:
Not open for further replies.
  1. LcB838 Newcomer, in training

    So, I had a .txt file with my threat files and then i found a log file in the eset folder so i posted both. What are startups? Should i do something to have less?
  2. kimsland Ex-TechSpotter

    Firstly well done for the Eset scan, it removed some nasties ;)

    Also, if you are presently running any Torrent download manager, you would be best to exit it, or better yet uninstall it (since one of the Virus found was a torrent downloaded file)

    You can have a look at some of your Startups starting with Windows with this free program: http://www.mlin.net/StartupCPL.shtml
    And also disable as many as you don't want starting with Windows
    But generally they are the programs that are sitting near your system clock, bottom right of your screen)

    Ideally restart if any Startup entries were disabled, and then provide a new HJT Scan Log as an attachment

    We need to do one more scan (this one is lots quicker ;))
    GMER: http://www2.gmer.net/gmer.zip
    Run the gmer program then copy the results to a new reply (its usually quite quick)

    Also let me know how its performing now? Any issues still?
  3. LcB838 Newcomer, in training

    Ok Update, I am not attaching the HJT file because when i hit scan and save log it just had a .txt file pop up that was saved 2 days ago. I didnt get the control panel program to work but I just went in and manually told 3 or 4 programs to not start up when i start windows.

    So, when i ran the gmer program the screen popped up, two things about avast would go in the screen. I would hit scan, quite a few file names started flooding the screen and boom, went to a blue screen said, found a problem with windows, shutting down before something. Then it would restart my computer. Did it twice, happened twice. So, I really don't have any .txt files for you.

    Really other then the cannot execute C:/windows/system32/memh.exe file that pops up at the start, As far as I can tell the computer runs fine. I do see the file in my HJT report and you had me click and say fix on that. But nothing has changed. Thoughts?
  4. LcB838 Newcomer, in training

    Ok lie haha, I decided to hit the file and no hit scan and see what i can do. Well it has numerous tabs. Processes, Modules, Files, Malware(the only two files under this are AVAST (my antivirus)) and so so is there a certain tab you want me to save and post?
  5. kimsland Ex-TechSpotter

    Check that C:/windows/system32/memh.exe is gone

    Start > Run > C:/windows/system32 > ok
    Then search for memh.exe
    You can either rename it to memh.old, or just delete it

    Yes highlight all and saved to Notepad, and attach here
  6. LcB838 Newcomer, in training

    Well the only thing i was able to save or copy was the malware section and that is attached. I deleted the memh file and when i restarted my computer nothing happened so as long as that was not an important .exe file I think i am set. Weird stuf :)
  7. kimsland Ex-TechSpotter

    Looks ok

    Uninstall SUPERAntispyware
    Start > Control Panel > Add/Remove Programs > SUPERAntispyware > Uninstall



    Udate Java and remove older Java versions
    Run JavaRa
    This will remove all your old Java stuff (that is not required)
    It will also help you check for new Java updates Runtime updates
    Or just go here and auto check: http://java.com/en/download/installed.jsp?detect=jre&try=1



    Download and run TFC http://oldtimer.geekstogo.com/TFC.exe
    Your computer may need to Restart



    Remove old System Restore Points

    • Open System by clicking the Start button [IMG], right-clicking Computer, and then clicking Properties.
    • In the left pane, click System protection [IMG]. Administrator permission required If you're prompted for an administrator password or confirmation, type the password or provide confirmation.
    • Under Protection Settings, click the disk, and then click Configure.
    • Click Turn off system protection, click OK, and then click OK again.
    Then turn it back on again.
  8. LcB838 Newcomer, in training

    why do i want to remove all system restore points?
  9. kimsland Ex-TechSpotter

    Standard practice on the completion of a Malware Topic ;)
  10. LcB838 Newcomer, in training

    I have the latest Java, Deleted all the old ones. Used the program to remove all the temp crap :) and removed all restore points (kinda terrifying) But I have no error messages, I have all the programs I want running well. So, I am glad to have protection on starting now. You have taught me quite a bit. i just recently heard of restore points, now I at least know where to find them :) Thank you so much, YOU TOO Surfer.
Thread Status:
Not open for further replies.