Member Panel


Sponsors and Ads

Noticeboard

PC Forum PC Help Forum » Security & Safety » [Fixed] Hijackthis! Logs » [Resolved] Malware and system restore errors

[Fixed] Hijackthis! Logs - [Resolved] Malware and system restore errors posted in the Security & Safety forums; Please bear with me here, I'm not great with technical jargon! Yesterday my computer picked upsome malware, which Avast detected straight away. I quarantined the trojans found, but whenever I ...

JOIN US NOW to remove these Ads

Post New Thread  Reply
  #1  
Old 02-20-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Question [Resolved] Malware and system restore errors

Please bear with me here, I'm not great with technical jargon!

Yesterday my computer picked upsome malware, which Avast detected straight away. I quarantined the trojans found, but whenever I rebooted the computer, Avast popped up warnings, having re-detected them.

I tried to read up on how to remove infected files from the system folder (where they appeared to be) and saw that you can disable System Restore, cleanup the computer and then enable it once all infected files have been removed.

I downloaded AVG Anti-Spyware to see if it could pick up anything Avast missed, which it seemed to - it found a few Backdoor type nasties which have now been quarantined, and since then nothing has been detected automatically after rebooting.

But I now can't access the system restore feature at all - i get an error message saying 'System restore is Unable to protect your computer. Please restart ....'

Can I be confident that all infected files have been removed and there's nothing left lurking? What's happened to system restore, which was working properly a few days ago? Is there any easy way to repair it?

I've attached a hijackthis log file in case it's of any use.
Attached Files
File Type: log hijackthis.log (8.2 KB, 2 views)


  #2  
Old 02-20-2007
upgrader's Avatar
Site Manager
My PC
 
Join Date: Jul 2006
Location: /home/upgrader/
Posts: 6,451
PC Experience: Some Experience
upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page upgrader - See this Members User comments on their Profile page
Send a message via MSN to upgrader Send a message via Skype™ to upgrader
Default

Welcome to PCHF kohl!

A security analyst will be with you soon.

[Moved to Hijackthis Logs]

Chris


__________________
PCHF Rules--PCHF Prework--PCHF Downloads
  #3  
Old 02-20-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

first off, how much disk space do you have left?

Secondly, have you run through the prework in either upgrader's or my signatures? That would be a good first start; then we can see both the AVG log AND the revised HJT log....I've got an idea of how we're going to fix this regardless, but I want to make sure that nothing is hiding in the wings.

Thanks,

v


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #4  
Old 02-20-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

Thanks for the replies .. I have 52 G of disk space left.

I did go through the prework - and the HJT log is from after having done that. Sorry, I forgot to attach the AVG log. I'll do that now.
Attached Files
File Type: txt 20-02-07.txt (42.8 KB, 2 views)


  #5  
Old 02-20-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

save the attached file to your desktop, and rename it to fix_restore.reg. Once that is done, double click on the .reg file, you will be prompted if you really want to do this, choose 'yes', it will then say 'successfully merged', reboot your system and see if you can get into the restore functions now.

Thanks,

v
Attached Files
File Type: txt fix_restore.txt (2.3 KB, 1 views)


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall
  #6  
Old 02-20-2007
Bronze Member
 
Join Date: Feb 2007
Posts: 16
kohl - See this Members User comments on their Profile page
Default

I still get the same error message I'm afraid


  #7  
Old 02-20-2007
valis's Avatar
Senior Security Analyst
My PC
 
Join Date: Jan 2007
Location: texas, USA
Posts: 2,627
PC Experience: PC Illiterate
valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page valis - See this Members User comments on their Profile page
Default

what the?!?!?!

grrrr...stupid computers......okay, let's go back a few steps.....obviously something doesn't want you to make changes, so let's try this....

Please go HERE to run Panda's ActiveScan
  • Once you are on the Panda site click the Scan your PC button
  • A new window will open...click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)
  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to a convenient location. Post the contents of the ActiveScan report


__________________

M.C.S.A.
M.C.P.
- MS Server 2k3, Network Architecture

"Ask Bill why the string in function 9 is terminated by a dollar sign. Ask him, because he can't answer. Only I know that."
- Gary Kildall

Reply
Satellite TV on your PC - over 3000 Channels! Click Here!

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are On

All times are GMT +1. The time now is 07:37 PM.
Powered by vBulletin
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
SEO by vBSEO 3.2.0 RC7
All Graphics & Content Copyright © 2004-2008 - PC Help Forum.com


Back to Top