Author Topic: Registry keys infected and system restore disabled  (Read 11313 times)

0 Members and 1 Guest are viewing this topic.

Online DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89052
  • No support PMs thanks
Re: Registry keys infected and system restore disabled
« Reply #15 on: May 15, 2010, 03:20:04 PM »
You're welcome.
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.3.6108 (build 24.3.8975.762) UI 1.0.801/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Registry keys infected and system restore disabled
« Reply #16 on: May 15, 2010, 05:14:58 PM »
It was a generic trojan downloader that never got a good grip on your system

Please download Malwarebytes' Anti-Malware from Here.

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish,so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:

If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

surfy

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #17 on: May 15, 2010, 07:20:14 PM »
Hi,
Thank you.
Here is the log attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Registry keys infected and system restore disabled
« Reply #18 on: May 15, 2010, 08:26:54 PM »
Nice and clean - what problems remain ?

surfy

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #19 on: May 16, 2010, 12:57:37 AM »
Hi,
Thank you. It's working fine.
The only thing I suspect is that my son used his laptop to downloaded a game onto his flash drive. He then put the flash drive on my desktop. When I turned on the desktop Avast would not start. I had to reinstall.
I ran OTL and GMER on the desktop and attached the logs. Can you see anything suspicious here?

Thanks again.
 :)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Registry keys infected and system restore disabled
« Reply #20 on: May 16, 2010, 01:33:20 PM »
Nothing apparent - but I would recommend wiping the flash drive and then running MBAM on the desktop

surfy

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #21 on: May 16, 2010, 02:26:06 PM »
Thank you very much. You're always a great help. :)

If I can please ask you for a recommendation.

I have the following installed: Avast 5.0.545, Super antispyware, spyware blaster, malwarebytes free version and windows xp firewall.

Is there another firewall you can recommend for an average user? I've heard of comodo, zone alarm and outpost, online armor but not sure which one to go for.

Thank you so much!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Registry keys infected and system restore disabled
« Reply #22 on: May 16, 2010, 02:47:42 PM »
They all have their good and bad points

Zone Alarm is getting bloated
Comodo does not work to well with Avast - or any other AV come to that
Outpost seems reasonable along with online Armour..

surfy

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #23 on: May 17, 2010, 03:30:54 PM »
Hi,

Thank you for your reply.

I installed online Armor and everything seems to be fine.

I then tried to update Java Sun. I downloaded the latest version and then tried to remove the older ones. Java 6 update 11 will not remove.
I then tried to install the new update but I get an error 1721 Problem with windows installer. Program required to install could not be run.

I'm not sure what I should do to correct this problem.

Thanks again.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Registry keys infected and system restore disabled
« Reply #24 on: May 17, 2010, 08:19:59 PM »
Ah that is part of the Java nightmare - I will have to check it out.  But last time I came across this the fix was: Uninstall all Java, remove all Java or Sun folders that are present on the system (including system32) then reinstall afresh 

surfy

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #25 on: May 19, 2010, 07:27:14 PM »
Hi,
Thanks for the info.
I deleted all folders but Java older version would not uninstall from control panel. I then downloaded windows installer clean up and it removed the stubborn Java version. The new version then installed smoothly. Just thought I'd post this solution in case anyone else is having a hard time.
Thanks again for your help.
 :)

YoKenny

  • Guest
Re: Registry keys infected and system restore disabled
« Reply #26 on: May 19, 2010, 09:33:51 PM »
@ surfy

DavidR an avast! Überevangelist has his system information in his signature so please go to PROFILE then Modify Profile then Signature: and put information about your system just like my signature about your system just like my signature so that the helpers can offer pertinent advice.