also @ TechSpot: Google, Samsung unveil Chromebook, Chromebox with Chrome OS 19

TechSpot

System restore probs, am I still infected?

Discussion in 'Virus and Malware Removal' started by daveki, Dec 6, 2009.

Thread Status:
Not open for further replies.
  1. daveki Newcomer, in training

    hi bobbye

    i did the online scan and have attatched the log!
    in an earlier post you also told me to remind you how to get control of the tracking cookies.

    thanks for all your help

    dave
  2. Bobbye Helper on the Fringe

    About the Tracking Cookies (thank): this needs to be done on accounts for both 'dave' and 'lee':

    Reset Cookies

    For Internet Explorer: Internet Options (through Tools or Control Panel) Privacy tab> Advanced button> CHECK 'override automatic Cookie handling'> CHECK 'accept first party Cookies'> CHECK 'Block third party Cookies'> CHECK 'allow per session Cookies'> Apply> OK.

    Now you can remove the cleaning tools and old restore points:


    Uninstall ComboFix.exe And all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
      [IMG]

    Remove all of the tools we used and the files and folders they created
    • DownloadOTCleanIt by OldTimer
    • Save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • If you are prompted to Reboot during the cleanup, select Yes.
    The tool will delete itself once it finishes.

    If you are prompted to Reboot during the cleanup, select Yes.


    You should now set a new Restore Point to prevent infection from any previous Restore Points. The easiest and safest way to do this is:
    • Go to Start > All Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the Restore Point a name then click "Create". The new Restore Point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Go to "Disk Cleanup" which can be found by going to Start > All Programs > Accessories > System Tools.
    • Click "OK" to select the partition or drive you desire.
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.

    More details and screenshots for Disk Cleanup in Windows Vista can be found here.

    The system will set new restore points once in about every 24 hours if the computer is on. You can also set your own any time you want. Wait a few days, then set a restore point for the day before. Next day, try restoring to that date to make sure it's working okay.

    Let me know if I can be of further help.
  3. daveki Newcomer, in training

    hi bobbye

    i followed your instructions cleaned all the files and folders used then had to reboot
    then i started to create a new restore point as you said by Go to Start > All Programs > Accessories > System Tools and click "System Restore". at this point as before i get this message "system restore is not able to protect your computer, please restart your computer then run system restore again" why would this be the case? i thought it should run ok now, wat could be the reason for this?

    thanks for all ur help

    dave
  4. Bobbye Helper on the Fringe

    System Restore Troubleshoot: Go through this please:

    Q.What should I do if System Restore does not work?
    A.Try these steps if System Restore does not appear to work:

    1.Ensure the System Restore service is running. For more information, see: How can I verify that the System Restore services are running on my machine? (see site)

    2.Verify that you have enough free space on all your drives as required by System Restore. If the free space on any partition system restore is monitoring falls below 50 MB, System Restore will suspend and purge out all restore points to free up disk space. It will automatically reactivate when 200 MB+ free space is available. For more information, see How the System Restore Tool Handles Hard-Disk Space Usage. (see site)

    3.Examine event logs for any system restore-related errors that could help you identify the problem.

    Start> Run> type in eventvwr

    Do this on each the System and the Applications logs:
    [1]. Click to open the log>
    [2]. Look for the Error>
    [3] .Right click on the Error> Properties>
    [4]. Click on Copy button, top right, below the down arrow >
    [5]. Paste here (Ctrl V)
    [6].NOTES
    • You can ignore Warnings and Information Events.
    • If you have a recurring Error with same ID#, same Source and same Description, only one copy is needed.
    • You don't need to include the lines of code in the box below the Description, if any.
    • Please do not copy the entire Event log.

    Errors are time coded.

    http://www.microsoft.com/technet/prodtechnol/winxppro/plan/faqsrwxp.mspx


    Try this and see what you get:
    Boot into Safe Mode: Start> Run> cmd> type in:
    C:\Windows\system32\Restore\rstrui.exe

    which is the Restore program, it will prompt with Create vs Restore and you can pick
    a Restore point.
    __________________
  5. daveki Newcomer, in training

    hi bobbye

    her is my errors from the event log not sure what they mean, could do with your view if possible:

    Application log:

    Event Type: Error
    Event Source: Intel(R) AMT
    Event Category: UNS
    Event ID: 2002
    Date: 19/12/2009
    Time: 23:33:04
    User: N/A
    Computer: DAVESLAPTOP
    Description:
    [UNS] Failed to subscribe to local Intel(R) AMT.

    Event Type: Error
    Event Source: LMS
    Event Category: None
    Event ID: 2
    Date: 19/12/2009
    Time: 23:33:01
    User: NT AUTHORITY\SYSTEM
    Computer: DAVESLAPTOP
    Description:
    LMS Service cannot connect to HECI driver

    system:

    Event Type: Error
    Event Source: Service Control Manager
    Event Category: None
    Event ID: 7026
    Date: 19/12/2009
    Time: 23:33:07
    User: N/A
    Computer: DAVESLAPTOP
    Description:
    The following boot-start or system-start driver(s) failed to load:
    Beep

    Event Type: Error
    Event Source: Service Control Manager
    Event Category: None
    Event ID: 7026
    Date: 19/12/2009
    Time: 22:44:41
    User: N/A
    Computer: DAVESLAPTOP
    Description:
    The following boot-start or system-start driver(s) failed to load:
    Beep

    im going to try booting into safemode as you said and will be report back with the results

    thanks once again! much appreciated

    dave

    hi bobbye

    i tried in safemode like you suggested and still received the same message as before"system restore is not able to protect your computer, please restart your computer then run system restore again" have u any ideas whats causing this?

    dave
  6. Bobbye Helper on the Fringe

    We've handled the malware. Now you are showing a hardware problem. I've put the following together for you. Please copy it and paste it into either the Windows OS forum or the general Hardware forum. You will get better help for this in one of those forums.

    You have:
    C:\Program Files\Intel\AMT\UNS.exe
    C:\Program Files\Intel\AMT\LMS.exe


    and related Services with Errors:
    O23 - Service: Intel(R) Active Management Technology Local Management Service (LMS) - Intel Corporation - C:\Program Files\Intel\AMT\LMS.exe
    Event Type: Error
    Event Source: LMS

    Event Category: None
    Event ID: 2
    Date: 19/12/2009
    Time: 23:33:01
    User: NT AUTHORITY\SYSTEM
    Computer: DAVESLAPTOP
    Description:
    LMS Service cannot connect to HECI driver

    and related Service:
    023 - Service: Intel(R) Active Management Technology User Notification Service (UNS) - Intel Corporation - C:\Program Files\Intel\AMT\UNS.exe
    Event Type: Error
    Event Source: Intel(R) AMT

    Event Category: UNS
    Event ID: 2002
    Date: 19/12/2009
    Time: 23:33:04
    User: N/A
    Computer: DAVESLAPTOP
    Description:
    [UNS] Failed to subscribe to local Intel(R) AMT.
  7. daveki Newcomer, in training

    thanks bobbye for all your help, much appreciated!

    :grinthumb
  8. Bobbye Helper on the Fringe

    You're welcome.
Thread Status:
Not open for further replies.