This thread's last reply is from March 17, 2009, 11:20 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
pc plodder
Hi John
Many many thanks for your help with this problem, The P.C seems to be running a lot better now thanks to all your instructions and tools you told me to use.
I will slowly digest what you have written about the extra bits and pieces for keeping my system clean etc. I will certainly join the complaints forum although what i'd like to do to the people responsible may not be suitable for the general members to read!!!!!
John, should i now uninstal combofix, atf cleaner, malewarebytes or should i leave them on my P.C?
Point taken about internet explorer. I do have firefox installed on the P.C and shall endevour to use it from now on.
Thanks again for all your help. Without people like yourself, myself and many others i suspect would be in grave trouble with P.C problems.
Thanks again
Regards
Steve
pc plodder
Hi John
Yes, confirm i have read the last post.
I have no more questions regarding the topic.
Once again thanks for all your help.
I think now you can mark this case as resolved.
Thank you
Regards
Steve
P.S I have not had one instance since you cleaned my P.C of it refusing to restart so it must have been to do with maleware that you removed.
pc plodder
John
I have a problem in that i can't uninstall combofix. I typed it in the run command as you said and it says "can't find combofix". Any ideas?
The icon has disappeared from the desktop and a search reveals nothing found.
I ran the OTCleanit as you advised It rebooted the p.c but atf cleaner and malewarebytes were still there. I have manually deleted them and done a search to check if they were still on the system but it appears they have been deleted sucessfully.
Your observations please.
Steve
pc plodder
Hi John
I've done what you said to the letter. It keeps putting a warning box up "cannot find ComboFix/u" Any ideas what the problem is? The combofix icon is on the desktop (i haven't installed it just downloaded it)
Regards
Steve
John B.
There needs to be a space between 'x /' of 'ComboFix /u', so it is like this 'ComboFix<space>/u'.
pc plodder
Hi John
Yes tried that....same response.
Is there anything else i should be doing to get rid of it like unticking the show hidden fikles etc as you told me to do in an nearlier post when we were running the scans.
Regards
Steve
pc plodder
John
Did all you asked.
Copying did not work, still there still the same message.
Did all the other things and all folder options are back to normal and i have only the one restore point that i created today.
I did another malware scan after i'd copleted all the tasks you gave me and i post the log below.
All my virus files are up to date with eset and spywareblaster files are up to date.
Maybe this stuff was hiding in a restore point that i deleted??
I also looked fot that twext file which came up on the scan but can't find in.
Log below. Your observasions please.
Malwarebytes' Anti-Malware 1.34
Database version: 1854
Windows 5.1.2600 Service Pack 3
16/03/2009 12:32:52
mbam-log-2009-03-16 (12-32-44).txt
Scan type: Full Scan (C:\|)
Objects scanned: 179185
Time elapsed: 24 minute(s), 41 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 3
Folders Infected: 1
Files Infected: 4
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows.0\system32\twext.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: system32\twext.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS.0\system32\userinit.exe,C:\WINDOWS.0\system32\twext.exe,) Good: (userinit.exe) -> No action taken.
Folders Infected:
C:\WINDOWS.0\system32\twain_32 (Backdoor.Bot) -> No action taken.
Files Infected:
C:\WINDOWS.0\system32\twain_32\local.ds (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twain_32\user.ds (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twain_32\user.ds.cla (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twext.exe (Backdoor.Bot) -> No action taken.
BTW i have deleted all as they were checkmarked.
pc plodder
Hi John
Sorry, didn't explain fully in my last post. Saved the log before i deleted all the checked items.
It did say after i'd done that to restart my P.C as some of the stuff couldn't be cleaned exept by a restart. Restarted the P.C did a virus scan with eset, scan with superantispyware then did another scan with malwarebytes and all came back with no infections, so it looks like the system is clean.
Sorry for my ignorance but i don't know what you mean by dual boot. The only thing i can think of is that when i boot the P.C up i get a black screen that stays on for about 3 seconds and shows windows twice and recovery consule then it carries on booting up as normal. Must say that screen has only appeared since i installed the recovery consul as advise by one of the peices of software (think it may have been Combofix) that you had me run in the beginning.
I've heard the term partitian before and know it's something to do with the hard drive, other than that i just boot the P.C up and use it. The file system is NTFS if that's any use.
Regards
Steve
pc plodder
Hi John
All understood.
BTW I ran all the scans again today (p.m) and again it's clean so job done i think.
Once again thanks for all your help, if it hadn't been for your assistance i would still have been stumling around in the dark.
Thanks once again
Regards
Steve
NonSuch
As this issue appears to be resolved,