Please Review My Logs

Discussion in 'Malware Help (A Specialist Will Reply)' started by markdex, May 10, 2006.

  1. markdex

    markdex Private E-2

    Thanks for your previous help with my son's laptop.

    Here is the logs from my desktop that I would like help with cleaning-up. I have followed all of your "Read Me First" steps. I am having no specific problems just a slow machine.

    Thanks.

    Mark
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Your log shows Java 1.4.2_04 installed and active and shows Java 1.5.0_06 in the registry keys. Uninstall the old version and make sure the installation was completed for 1.5.0_06. You may have to uninstall 1.5, download and reinstall.

    http://javashoplm.sun.com/ECom/docs/Welcome.jsp?StoreId=22&PartDetailId=jre-1.5.0_06-oth-JPR&SiteId=JSC&TransactionId=noreg

    Your install of BSafe may be broken, the O10 entry shows a file to be missing that is part of BSafe. Check and make sure that it is not in fact missing, C:\WINDOWS\system32\InetCntrl\InetCntrl.exe. If it is missing you may need to reinstall BSafe.

    Copy the contents of the below quote box to notepad and save as FixReg.reg to your Desktop.
    Double-click FixReg.reg and answer 'Yes'.

    Remove the following from the Internet Explorer Trusted Zone:

    http://download.windowsupdate.com

    There should be nothing in the IE Trusted Zone. Yes, I know that MS tells you to do this as part of a fix when Windows Update is not working. If Windows Update stops working, there are other fixes we can try without putting Windows Update in the Trusted Zone.

    Scan with HijackThis and fix the following lines:
    Download
    - Pocket Killbox
    - ExplorerXP

    Now run Pocket Killbox:

    Choose Tools -> Delete Temp Files and click the RED X.

    Run Killbox.exe. Paste the below filenames into KILL BOX one at a time. Check mark the box that says "Delete on Reboot" and checkmark the box "Unregister DLL" (If available) Click the RED X and it will ask you to confirm the file for deletion say YES and when the next box opens prompting you to reboot now...click NO...and proceed with the next file. Once you get to the last one click YES and it will reboot. Note many of the file list below may not exist but we need to check for them anyway.
    If Killbox does not reboot or you get a Pending Operations type error message just reboot your PC yourself.

    Now boot into SAFE MODE

    Open Windows Explorer navigate to and DELETE the following: (Some of these may have already been deleted by Pocket Killbox)
    Now run CCleaner. If you have Windows XP delete the contents of C:\WINDOWS\Prefetch.

    Then, as an added precaution, Go to Start -> Run and type: cleanmgr and then click OK. Make sure the boxes for these are checked:
    Temporary Files
    Temporary Internet Files
    Recycle Bin


    And Click OK.

    REBOOT to Normal Mode.

    Delete FixReg.reg from the Desktop.

    Run ExplorerXP navigate to and complete the action as indicated for the below file.
    Empty the Recycle Bin.

    Run CCleaner

    Disable system Restore, as per this thread, Disable And Enable System Restore.

    REBOOT

    Enable System Restore.

    Post a fresh HijackThis log.
     
  3. markdex

    markdex Private E-2

    Thanks for your help.

    All steps completed. Here is a new HJT log.

    Thanks.
     

    Attached Files:

  4. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds