Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Login to participate.
|
|||||||
Had Trojans and malware and Vundo
![]() |
|
|
|
Thread Tools |
|
#1
|
|||
|
|||
|
Had Trojans and malware and Vundo
Hi:
I just completed the last step of "viruses / Spyware / Malware, Prelimnary Removal Instructions" Here are my Log files. From HJT, combofix, & SAS. Every thing seams to work better then it has been in a long time. the only Problem I see is the clock is now on 24 hour time. But I will check tomarrow. Couple of Questions. 1. Should I Remove the old Update files from Microsoft? How? 2. When all this started I had problems with my Browser and could not Sign into my Yahoo accoount cause my Browser was not excepting Cookies. is there a setting I should cheak? 3. Should I set a new restore point? 4. Should I unstall all or some of the programs I used to clean the PC ? Thanks In Advance. Turk Last edited by Turkman57; 08-16-2008 at 03:15 AM.. Reason: ? |
|
#2
|
||||
|
||||
|
OK your HJT log looks clean. Havent looked through combofix and other one yet.
Reply to number 3- You should always set a restore point after major updates or at least once every 2-3 months. This will let you rewind time back to the point where you saved the point. It may take up a pit of space but hey, its worth it. Also, somewhere there should be a setting to turn on cookies, probably in internet options (not sure because i have never had to turn them on) but you should find that setting and turn it on. |
|
|
|
#3
|
||||
|
||||
|
That's not a clean hijackthis log it still shows vundo
======================================================= Afterwards attach the MBAM log with a fresh Hijackthis |
|
#4
|
|||
|
|||
|
cleaned with malware bytes
Ok , I ran Mbam heres the log. thanks in advance
Turk |
|
#5
|
||||
|
||||
|
Still there
Follow this and post the logs back here for me... http://www.techspot.com/vb/post645589-1.html |
|
#6
|
|||
|
|||
|
Am I clean yet?
Hi :
The only 3 problems i see is 1. When i ran Mcafee it found 1 Item "Rem adm-proclaunch 171" it was for Combofix 2. When I ran mabam I lost the log the screen said 1 item detected. 3. one left over from the start of this. When i click on "Install Update Manger" it says "Agent Not found". Thanks In Advance Turk |
|
#7
|
||||
|
||||
|
1) Combofix quarantined a lot - I am surprised it didn't find more
2) The instructions state how to find the MBAM log - but either way we can fix you up 3) What update manager are you installing? =========================================================== Backup your regsitry First, we need to backup your registry: Please go to Start > Run Paste in the following line:
It won't appear to be doing anything, that's normal. Your mouse pointer may turn to an hour glass for a minute. Please continue when it no longer has the hour glass. Making a .reg file Open notepad and copy and paste the text in the quotebox below in it: Code:
REGEDIT4 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"="" Change the "Save As" type to "All Files" and save it on the desktop. It should look like this: ![]() Double-click on it and when it asks you if you want to merge the contents to the registry, click yes/ok. ======================================================= OTMoveit2 by OldTimer Please download the OTMoveIt2 by OldTimer.
======================================================= Run Kaspersky Online AV ScannerIn order to use it you have to use Internet Explorer. Go to Kaspersky and click the Accept button at the end of the page. Note for Internet Explorer 7 users: If at any time you have trouble with the accept button of the licence, click on the Zoom tool located at the right bottom of the IE window and set the zoom to 75 %. Once the license accepted, reset to 100%.
Last edited by Blind Dragon; 08-19-2008 at 11:21 PM.. |
|
#8
|
|||
|
|||
|
Am I clean yet 2
while kaspinsky was scanning an error popup the title was MIM has encountered a problem it belongs to Musicmatch.
other then that Move it found no files and kaspinsky found 2 infected files, but i found no way in the program to remove them. Thanks In advance Turk I noticed that the JAVA icon was on the task bar. I did some snooping around and found a Trace file. You mite be intrested in the bottom of the file where it says Virus. so here is a copy don't know if it helps Last edited by Turkman57; 08-20-2008 at 09:18 PM.. Reason: More info |
|
#9
|
||||
|
||||
|
That's clean -1 is in quarantine, the other is a false positive - we will remove both now
Uninstall Combofix * Click START then RUN * Now type Combofix /u in the runbox * Make sure there's a space between Combofix and /u * Then hit Enter. * The above procedure will: * Delete the following: * ComboFix and its associated files and folders. * Reset the clock settings. * Hide file extensions, if required. * Hide System/Hidden files, if required. * Set a new, clean Restore Point. ----------------------------------------------------------------------- Launch OTMoveit2! and click the green Cleanup! --------------------------------------------------------------------------- Now that you are clean, please follow these simple steps in order to keep your computer clean and secure:
here are some additional utilities that will enhance your safety
|
|
|
|
#10
|
|||
|
|||
|
Thank you very much
Hi :
1. When Moveti Rebooted me and i sign in Windows told me it could not load my profile and started me a new one like Day 1. After every thing calmed down I rebooted and signed in again and everything was back to normal. Thank You very much! Turk |
|
#11
|
|||
|
|||
|
HI :
1 More thing Should I delete the Reg file we made? Thanks |
|
#12
|
||||
|
||||
|
yes you can delete the reg file - it did its job
|
![]() |
| Thread Tools | |
|
|
| Similar Topics | ||||
| Topic | Category | Replies | Last Post | |
| Infected with Trojans and Malware | Virus & Malware removal | 10 | 07-18-2008 02:44 PM | |
| Malware/adware:trojan downloader.xs/abebot/mal vundo 4 | Virus & Malware removal | 12 | 05-07-2008 08:11 PM | |
| Need help with Malware/Spyware - IE windows popping up. Vundo? | Virus & Malware removal | 5 | 11-07-2007 04:20 AM | |
| repeating malware(ErrorCleaner, PrivacyProtector, Spyware&Malware Protect) plz help | Virus & Malware removal | 1 | 10-22-2007 07:36 PM | |
| Help, 3 in 1 regenerating malware ( error cleaner privacy protector/ spyware malware | Virus & Malware removal | 1 | 07-09-2007 06:02 AM | |
All times are GMT -4. The time now is 02:58 AM.




Run Kaspersky Online AV Scanner