sys restore

Discussion in 'Malware Help (A Specialist Will Reply)' started by seaside, Mar 25, 2005.

  1. seaside

    seaside Corporal

    is it safe to run sys restore after cleaning.also
    i run all the anti spyware stuff i did a on line scan and deleted a found trojen
    heres my new log is it clean
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    First:
    Close ALL browsers while running HJT.
    • F:\Program Files\Internet Explorer\iexplore.exe
    Second:

    Now scan with HijackThis and Check the Boxes for the following:

    Make sure All Browser Windows are Closed when you Click FIX.

    O2 - BHO: (no name) - {DE23A040-D6AA-43ca-9B86-D9BE3DAA6FE7} - F:\WINDOWS\system32\javafix4.dll

    O4 - HKCU\..\Run: [strto] f:\windows\strto.exe
    O4 - Startup: ERUNT AutoBackup.lnk.disabled
    O4 - Global Startup: SpySubtract.lnk.disabled

    O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptemplates/AktiveSekurity.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    F:\WINDOWS\system32\javafix4.dll

    F:\WINDOWS\strto.exe

    NEXT:
    Run CCleaner


    Reboot to Normal Windows , Scan with HijackThis and attach the new log to be sure we got them:)
     
  3. seaside

    seaside Corporal

    hi i did all you asked re-

    O2 - BHO: (no name) - {DE23A040-D6AA-43ca-9B86-D9BE3DAA6FE7} - F:\WINDOWS\system32\javafix4.dll

    O4 - HKCU\..\Run: [strto] f:\windows\strto.exe
    O4 - Startup: ERUNT AutoBackup.lnk.disabled
    O4 - Global Startup: SpySubtract.lnk.disabled

    O16 - DPF: {0F9B4CA4-A30F-480A-841D-69B45C50A8F8} (SekureL0gin.SekureKontrol) - http://secure2.comned.com/signuptem...iveSekurity.cab

    Again, make sure All Browser Windows are Closed when you Click FIX.

    NOW:
    Please boot into Safe Mode with the Viewing of Hidden Files & Folders Enabled and navigate to and DELETE the following if they should remain:

    F:\WINDOWS\system32\javafix4.dll

    F:\WINDOWS\strto.exe
    i could not find F:\WINDOWS\system32\javafix4.dll

    F:\WINDOWS\strto.exe
    in my f drive here is my new log
    now i cannot upload my hijack this log doh!
    it says write access denied to the location you specified tyr a different location please
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Try to upload it again, if no success paste it and I will have it converted into an attachment.
     
  5. seaside

    seaside Corporal

    i seem to have clicked read only on the note pad thing heres my new log i hope
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    That log is clean my friend! :)

    Are you have any further problems?
     
  7. seaside

    seaside Corporal

    no mate once again you guys come up trumps thank you .will stay awhile its nice to sometimes watch you people fix a well bugged computer
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Its fun for me, I love a challenge! :D
     
  9. seaside

    seaside Corporal

    your a real nice person bjgarrick
     
  10. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Thank You! :)

    That's what I do this for:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds