SpyWare BeWare! ASAP
May 24, 2013, 02:19:06 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
   Home   Help Search Calendar Donations Login Register Chat  



Google It!
Pages: 1 [2]   Go Down
  Print  
Author Topic: e-crimes virus  (Read 1196 times)
0 Members and 1 Guest are viewing this topic.
Hamturk
Jr. Member
**
Offline Offline

Date Registered:March 19, 2012, 02:54:59 AM
Posts: 77


« Reply #15 on: March 19, 2012, 12:53:24 PM »

Here they are.
Logged
MrCharlie
Moderator
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6593



WWW
« Reply #16 on: March 19, 2012, 01:47:42 PM »

Please do this:

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following in blue:

    :OTL
    O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
    O4 - Startup: C:\Users\Danielle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk =  File not found
    O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk =  File not found
    O4 - Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk =  File not found
    O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk =  File not found
    O4 - Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk =  File not found


  • Then click the Run Fix button at the top
  • Let the program run unhindered, when done it will say "Fix Complete press ok to open the log"
  • Please post that log in your next reply. Note: If a file or folder cannot be moved immediately you may be asked to reboot the machine to finish the move process. If you are asked to reboot the machine choose Yes. In this case, after the reboot, open Notepad (Start->All Programs->Accessories->Notepad), click File->Open, in the File Name box enter *.log and press the Enter key, navigate to the C:\_OTL\MovedFiles folder, and open the newest .log file present, and copy/paste the contents of that document back here in your next post.

MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Hamturk
Jr. Member
**
Offline Offline

Date Registered:March 19, 2012, 02:54:59 AM
Posts: 77


« Reply #17 on: March 19, 2012, 01:55:11 PM »

========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
C:\Users\Danielle\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk moved successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk moved successfully.
C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk moved successfully.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk scheduled to be moved on reboot.
File move failed. C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk scheduled to be moved on reboot.
 
OTL by OldTimer - Version 3.2.39.1 log created on 03192012_184957

Files\Folders moved on Reboot...
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\LaunchCenter.lnk not found!
File\Folder C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\newreminderdialog.lnk not found!

Registry entries deleted on Reboot...
Logged
MrCharlie
Moderator
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6593



WWW
« Reply #18 on: March 19, 2012, 02:09:59 PM »

How's the computer now??  MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Hamturk
Jr. Member
**
Offline Offline

Date Registered:March 19, 2012, 02:54:59 AM
Posts: 77


« Reply #19 on: March 19, 2012, 02:18:20 PM »

As I said in my first post I didn't have anymore issues with computer locking, so I cant really say on that point, but the "caution you're trying to open files used by operating system" is gone.

I still had the delay logging in and the desktop still took longer than usual to fully load.
Logged
MrCharlie
Moderator
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6593



WWW
« Reply #20 on: March 19, 2012, 02:33:04 PM »

Well if you still think there's problems.....do this:

Please download and run ComboFix.
The most important things to remember when running it is to disable all your malware programs and run Combofix from your desktop.

Please visit this webpage for download links, and instructions for running ComboFix

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Information on disabling your malware programs can be found Here.

Make sure you run ComboFix from your desktop.   

Please include the C:\ComboFix.txt in your next reply for further review.

MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Hamturk
Jr. Member
**
Offline Offline

Date Registered:March 19, 2012, 02:54:59 AM
Posts: 77


« Reply #21 on: March 19, 2012, 02:39:00 PM »

I just ran a full system scan with AVG antivirus and it said no threats detected, would you say this is sufficient to declare the computer safe?

Also, is it ok for me to run another scan with malwarebytes?
Logged
MrCharlie
Moderator
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6593



WWW
« Reply #22 on: March 19, 2012, 03:01:24 PM »

OK, run a Full Scan though,  MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Hamturk
Jr. Member
**
Offline Offline

Date Registered:March 19, 2012, 02:54:59 AM
Posts: 77


« Reply #23 on: March 19, 2012, 03:45:08 PM »

Malwarebytes also said it's fine.

Does this means everything is gone?
Logged
MrCharlie
Moderator
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6593



WWW
« Reply #24 on: March 19, 2012, 03:50:42 PM »

Well if the computer if fine, I'd say you're OK.

Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)

Any other programs or logs you can manually delete.
Any questions...please post back.
Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum,  MrC

Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  


Powered by MySQL Powered by PHP Powered by SMF 1.1.17 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!