Author Topic: AUTORUN-GEN and WIN32:CONFI defeated?  (Read 13374 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #15 on: May 17, 2011, 08:41:18 PM »
Could I have a fresh OTS log please also I assume your computer is a dell

mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #16 on: May 17, 2011, 10:54:14 PM »
her i am essexboy... thank for your patience.
i attach here new Ots scan log.

A few notes:
- i've a HP laptop
- this evening again pc going slow
- at windows start, avast did not start automatically as usual

Thanks

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #17 on: May 17, 2011, 11:00:52 PM »
A quick question whilst I look at the log - did you set the proxies in Firefox and IE ?

mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #18 on: May 17, 2011, 11:04:51 PM »
A quick question whilst I look at the log - did you set the proxies in Firefox and IE ?

i use only FF4
but... what are proxies???  ::)

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #19 on: May 17, 2011, 11:08:37 PM »
I think that answers my question  ;D

Start OTS. Copy/Paste the information in the quotebox below into the panel where it says "Paste fix here" and then click the Run Fix button.

Code: [Select]
[Unregister Dlls]
[Win32 Services - Safe List]
YN -> (Comodo Anti-Virus and Anti-Spyware Service) Comodo Anti-Virus and Anti-Spyware Service [Disabled | Stopped] ->
[Registry - Safe List]
< Internet Explorer Settings [HKEY_CURRENT_USER\] > ->
YN -> HKEY_CURRENT_USER\: "ProxyServer" -> 192.168.0.22:61380
< FireFox Settings [Prefs.js] > -> C:\Documents and Settings\user\Dati applicazioni\Mozilla\FireFox\Profiles\7rdnl2j2.default\prefs.js
YN -> network.proxy.backup.ftp -> "192.168.0.22"
YN -> network.proxy.backup.ftp_port -> 61380
YN -> network.proxy.backup.gopher -> "192.168.0.22"
YN -> network.proxy.backup.gopher_port -> 61380
YN -> network.proxy.backup.socks -> "192.168.0.22"
YN -> network.proxy.backup.socks_port -> 61380
YN -> network.proxy.backup.ssl -> "192.168.0.22"
YN -> network.proxy.backup.ssl_port -> 61380
YN -> network.proxy.ftp -> "192.168.0.22"
YN -> network.proxy.ftp_port -> 61380
YN -> network.proxy.gopher -> "192.168.0.22"
YN -> network.proxy.gopher_port -> 61380
YN -> network.proxy.http -> "192.168.0.22"
YN -> network.proxy.http_port -> 61380
YN -> network.proxy.no_proxies_on -> "localhost,127.0.0.1"
YN -> network.proxy.share_proxy_settings -> true
YN -> network.proxy.socks -> "192.168.0.22"
YN -> network.proxy.socks_port -> 61380
YN -> network.proxy.ssl -> "192.168.0.22"
YN -> network.proxy.ssl_port -> 61380
< BHO's [HKEY_LOCAL_MACHINE] > -> HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
YN -> {9AA2F14F-E956-44B8-8694-A5B615CDF341} [HKLM] -> Reg Error: Key error. [Reg Error: Key error.]
< Internet Explorer Extensions [HKEY_CURRENT_USER\] > -> HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Extensions\
YN -> CmdMapping\\"{08B0E5C0-4FCB-11CF-AAA5-00401C608501}" [HKLM] -> [Reg Error: Value error.]
YN -> CmdMapping\\"{CCA281CA-C863-46ef-9331-5C8D4460577F}" [HKLM] -> [@btrez.dll,-4015]
[File - Lop Check]
NY ->  Avg7 -> C:\Documents and Settings\All Users\Dati applicazioni\Avg7
[Custom Items]
:Files
ipconfig /flushdns /c
:end
[Empty Temp Folders]
[EmptyFlash]
[CreateRestorePoint]
 

The fix should only take a very short time. When the fix is completed a message box will popup telling you that it is finished. Click the Ok button and Notepad will open with a log of actions taken during the fix.  Post that information back here

I will review the information when it comes back in.


mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #20 on: May 17, 2011, 11:24:48 PM »
information attached
fix was quick but just at the end (during creation of the restore point) OTS and Pc seemed to freeze.

I typed CTRL+ALT+CANC e and system asked me to reboot... also reboot seemed to go bad (only a black screen with mouse cursor)

I restart manually Pc adnd then i get this log file anyway


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #21 on: May 18, 2011, 08:53:07 PM »
Quote
Total Files Cleaned = 107,00 mb
This was why the run took so long - a very full set of temporary files

What are your current problems


mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #22 on: May 18, 2011, 09:10:46 PM »
I see, thanks.

at the moment, i see only that Avast doesn't start automatically... or it seemed very slower to start.

I guess even that FF4 on this old machine doesn't fit...
Maybe i've to delete something on my hard drives, one of them is almost full...

Other suggestions?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #23 on: May 18, 2011, 09:37:54 PM »
Drive C: | 19,53 Gb Total Space | 3,39 Gb Free Space | 17,36% Space Free | Partition Type: NTFS
Drive D: | 36,35 Gb Total Space | 30,86 Gb Free Space | 84,90% Space Free | Partition Type: NTFS
Drive E: | 641,28 Mb Total Space | 0,00 Mb Free Space | 0,00% Space Free | Partition Type: CDFS

I would recommend moving data to your D drive as much as possible, then run a checkdisc and defrag on C

Download and run Puran Disc Defragmenter
For the first run I would recommend a boot defrag and disk check




mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #24 on: May 18, 2011, 09:43:15 PM »
ok, i try
thank you essexboy

mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #25 on: May 18, 2011, 11:02:01 PM »
done...

only Avast still non activate it self automatically at start as usual

i'll try to verifiy all settings in the options

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #26 on: May 18, 2011, 11:09:34 PM »
Run a repair on Avast go to add/remove and select Avast - on the left will be several options , select repair

mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #27 on: May 18, 2011, 11:27:34 PM »
done, great!

it seems all going well.

thanks a lot, essexboy.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #28 on: May 18, 2011, 11:46:40 PM »
Let it run for a day or so and when you are happy I will remove my tools

mulongo

  • Guest
Re: AUTORUN-GEN and WIN32:CONFI defeated?
« Reply #29 on: May 25, 2011, 09:37:00 PM »
hi essex boy,

i'm here again, after a few days - and after a good "cleaning" of my 2 HD's,

i register again slowness in all apps

a few minutes ago appeared an alert about a script blocking CPU with this referral:
"Script: resource://gre/components/nsBlocklistService.js:722"

What do yiu think about it?

Thanks!