Author Topic: AV Security 2012  (Read 11696 times)

0 Members and 1 Guest are viewing this topic.

Fran9932

  • Guest
Re: AV Security 2012
« Reply #30 on: November 21, 2011, 11:57:15 PM »
Sorry,
Here is the latest

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #31 on: November 22, 2011, 10:03:50 PM »
OK the registry entry for netbt did not look right

Could you go Start > Run
Type in  Regedit and press OK
When regedit opens navigate to the following key

HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\NetBT

Could you post a screen shot of the area as below


Fran9932

  • Guest
Re: AV Security 2012
« Reply #32 on: November 23, 2011, 09:32:07 PM »
Essexboy,
Screenshot is below:

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #33 on: November 23, 2011, 09:46:17 PM »
Do you have access to another XP computer ?

If so then go to that key in regedit
Right click the key
Select export
In the dialogue save it to the desktop as .reg file
Copy the reg file to your computer
Right click and select merge
Reboot and then try the net

Fran9932

  • Guest
Re: AV Security 2012
« Reply #34 on: November 23, 2011, 10:40:20 PM »
Can you hear all that singing!!!! I am on my desktop. Luckily, my neighbor had XP.  I assume that I need to remove all the combofix, etc. Just uninstall???

THANKS MIGHTILY!!!!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #35 on: November 23, 2011, 10:52:50 PM »
Yep once you are happy I will remove my rubbish so that you can get back to having fun....

Any further problems before I do that

Fran9932

  • Guest
Re: AV Security 2012
« Reply #36 on: November 25, 2011, 01:42:59 PM »
Looks like I am good to go. Only thing is the internet seems to be moving kinda slowly,,,,, I had a toggle key thing on my bottom bar. Ran Avast and they found a trojan and removed or quarantined and it disappeared. Was that spyware?

Do I just go to control panel and remove all the programs?

Thanks again

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37532
  • Not a avast user
Re: AV Security 2012
« Reply #37 on: November 25, 2011, 01:48:52 PM »
Quote
Ran Avast and they found a trojan and removed or quarantined and it disappeared. Was that spyware?
what does the log say ?
was it moved to chest ? what is the name ? where was it located


Quote
Do I just go to control panel and remove all the programs?
nope........but you should wait for essexboy first...he will tell if and how to

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #38 on: November 25, 2011, 07:03:57 PM »
Could you let me know what Avast removed please - within the virus chest it should give you the file name and location.


I will remove the tools cleanly at the end as none are in add/remove

Fran9932

  • Guest
Re: AV Security 2012
« Reply #39 on: November 26, 2011, 03:28:47 AM »
It was a win32 cybot trj and was moved to a chest
location was C:\...\A00012733.exe
Action was successful

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #40 on: November 26, 2011, 12:37:15 PM »
Ah that was in system restore - not a problem after this

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :Commands
    [resethosts]
    [emptytemp]
    [CLEARALLRESTOREPOINTS]
     [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Remove ComboFix
  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall
     (Notice the space between the "x" and "/")
    then click OK



  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
   Your Java is out of date.
Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

 Upgrading Java:
  • Go to this site  and click Do I have Java
  • It will check your current version and then offer to update to the latest version
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?Keep safe  :wave:

Fran9932

  • Guest
Re: AV Security 2012
« Reply #41 on: November 26, 2011, 01:59:40 PM »
Thanks
I have run programs as you asked.
I still have rkill on my desktop and reg
After running otl the reg changed from reg.reg to reg but when I click the icon on the deskton it still asks if I want to change my registry.

Never could get rkill to run so that might be why otl did not delete.

Few questions:
1)Why can't I disable my avast? Should I delete it and reinstall? It updates all the time.
2)Whenever I am booting, I get an icon for "sticky keys" on my bottom bar. It disappears but I wonder what in the world that is?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: AV Security 2012
« Reply #42 on: November 26, 2011, 02:50:15 PM »
Quote
still have rkill on my desktop and reg
Just delete these manually by right click


Quote
1)Why can't I disable my avast? Should I delete it and reinstall? It updates all the time.
How do you mean it updates all the time ?  It will check for updates every four hours and there is on average one or two updates at some stage during the day

Quote
2)Whenever I am booting, I get an icon for "sticky keys" on my bottom bar. It disappears but I wonder what in the world that is?
You have sticky keys enabled on your system

Go to Control Panel>Accessibility Options>Keyboard>Sticky Keys and uncheck "Use sticky keys".
OR
 try going to the Accessibility Options>Keyboard, click the Settings button on Sticky Keys and uncheck "Use Shortcut".