Submit Your Article Forum Rules FAQ About Us
Search the forums:

Tech Support Team


Hello and Welcome to Tech Support Team! Before you can start posting and answering questions, you'll have to register. Registration is fast, simple and absolutely free! Feel free to browse through existing questions by choosing the forum you want to visit below.



Notices

Closed Thread
  #1 (permalink)   Top
Old 10th February 2008, 07:23 AM
Blind Dragon's Avatar
TST Member
 
Join Date: Jan 2008, 165 posts.
Location: Tampa FL
Reputation: Blind Dragon is on a distinguished road
[SOLVED] double check HJT log

I cleaned a badly infected computer for a friend. It had smitfraud variety trojans, a ton of spyware, and Look2Me infection, over 400 registry problems, a few gigs of system clutter. I basically just spent 11 hours cleaning.

I think I got everything as the installed programs are gone from the desktop and there are no more redirects, I don't see anything else, but am quite tired at this point.

Would one of you mind doublechecking the HJT to make sure it looks ok.

thanks in advance
__________________
Tech-101

Last edited by Howard; 11th February 2008 at 07:12 PM.
  #2 (permalink)   Top
Old 10th February 2008, 07:29 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
That`s clean as a whistle mate.

However, you might want to do the following.

Download combofix.exe. Double click combofix.exe & follow the prompts. A window will open with a warning. Type "Y" (and Enter) to start the fix. When the scan completes it will open a text window. Please attach that log back here together with a fresh HJT log. Caution - do not touch your mouse/keyboard until the scan has completed. The scan will temporarily disable your desktop, and if interrupted may leave your desktop disabled. If this occurs, please reboot to restore the desktop.

Combofix will automatically save the log file to C:\combofix.txt, please post the log.

Regards Howard

This thread is for the use of Blind Dragon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #3 (permalink)   Top
Old 10th February 2008, 07:31 AM
Blind Dragon's Avatar
TST Member
 
Join Date: Jan 2008, 165 posts.
Location: Tampa FL
Reputation: Blind Dragon is on a distinguished road
I was already running a fresh combofix right after posting.

Here ya go
__________________
Tech-101

Last edited by Howard; 11th February 2008 at 07:12 PM.
  #4 (permalink)   Top
Old 10th February 2008, 07:42 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Open notepad and copy/paste the text in the code box below into it:
NOTE* make sure to only highlight and copy what is inside the quote box nothing out side of it.
Also ..

Pay particular attention to this :-

Make sure the word File:: is on the first line of the text file you save (no blank line above it, & no space in front of it)
Code:


Quote:
File::
C:\WINDOWS\system32\lo2.txtt
C:\WINDOWS\unins000.exe
C:\WINDOWS\unins000.dat
Save this as CFScript.txt

Then drag the CFScript.txt into ComboFix.exe as you see in the screenshot below.



This will start ComboFix again. After reboot, (in case it asks to reboot), post the contents of Combofix.txt in your next reply.

Regards Howard

This thread is for the use of Blind Dragon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #5 (permalink)   Top
Old 10th February 2008, 07:55 AM
Blind Dragon's Avatar
TST Member
 
Join Date: Jan 2008, 165 posts.
Location: Tampa FL
Reputation: Blind Dragon is on a distinguished road
tea timer keeps popping up asking permission to change SCR Extension handler -> Says "Value Changed" Old data = Notepad.exe %1 then New Data "%1" /S

I have been hitting Deny - any idea on that one? My guess is that it is because I deleted the redirects from the host file and installed the spybot hosts file
__________________
Tech-101

Last edited by Howard; 11th February 2008 at 07:13 PM. Reason: attaching log
  #6 (permalink)   Top
Old 10th February 2008, 08:03 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Your log file is clean.

Allow the alert in SS&D instead of hitting deny. It shouldn`t ask you again after that.


Click start/run and type combofix /u into the run box and hit the enter key. Note the space between combofix and forward slash. This will uninstall Combofix and all it`s folders etc.

Turn off system restore.(XP/ME only) See how HERE.

Now, turn system restore back on. This will have deleted all your old restore points and any nasties that are in them. It will also have created a new, clean restore point.


If you have any further virus/spyware problems, please post in this thread.

Regards Howard

This thread is for the use of Blind Dragon only. Please don`t post your own virus/spyware problems in this thread. Instead, open a new thread in our malware Removal forum.
  #7 (permalink)   Top
Old 10th February 2008, 08:05 AM
Blind Dragon's Avatar
TST Member
 
Join Date: Jan 2008, 165 posts.
Location: Tampa FL
Reputation: Blind Dragon is on a distinguished road
Thank you sir

Time to sleep finally

You can mark the thread Solved
__________________
Tech-101
  #8 (permalink)   Top
Old 10th February 2008, 08:06 AM
Howard's Avatar
TST Master
 
Join Date: Dec 2007, 3,366 posts.
Reputation: Howard has a spectacular aura aboutHoward has a spectacular aura about
Ok mate, consider it done.

Thread solved.

Regards Howard
Closed Thread

Only registered members can participate in forum threads. You must register or log in to contribute.


Thread Tools

Forum Jump


All times are GMT. The time now is 09:00 PM.






Post A Question!
Useful Links
Main Menu
Home
Forum Rules
FAQ
About Us
Welcome Pack
Search the forums
TST Mobile
Contact Us
Send Message

These are the 8 most used thread tags
Tag Cloud
geforce modem monitor no ring response no signal nvidia soft modem win7