1. Welcome Guest! In order to create a new topic or reply to an existing one, you must register first. It is easy and free. Click here to sign up now!.
    Dismiss Notice

[Solved] recently did format on windows 7

Discussion in 'Malware Removal Help' started by Just-Me, Mar 3, 2014.

  1. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    hope this is done correctly now...sorry about my mistake. I guess I don't have to empty tfc again do I?






    Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 13-03-2014
    Ran by Lila at 2014-03-23 19:07:02 Run:2
    Running from C:\Users\Lila\Desktop
    Boot Mode: Normal
    ==============================================

    Content of fixlist:
    *****************
    BHO-x32: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
    2014-02-27 09:25 - 2014-02-27 09:25 - 00003108 _____ () C:\Windows\System32\Tasks\{DEA80C2E-DC22-4722-AD6E-00BDC96E508C}
    AlternateDataStreams: C:\ProgramData\TEMP:5C321E34
    *****************

    HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
    HKCR\Wow6432Node\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB} => Key not found.
    "C:\Windows\System32\Tasks\{DEA80C2E-DC22-4722-AD6E-00BDC96E508C}" => File/Directory not found.
    "C:\ProgramData\TEMP" => ":5C321E34" ADS not found.

    ==== End of Fixlog ====
     
  2. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Yes that's what i wanted.
    You're the second today to make that mistake... so you're not alone. :)

    No you don't.

    How is the system running?... any problems?
     
  3. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    yes its running fine. I ended up with a couple of things my desktop that look like notepads. attaching a screen shot of them.

    also can I delete all of these programs you had me download? shall I keep the TFC and use it regularly? I have ATF on my desktop that I normally use regularly before I close down each day. Is it the same at the TFC?

    tyvm

    oh now I have another problem. just tried to go into my pictures and got a message. attaching a screen shot of that to. I had to save these pix to my documents. not allowed to get into my pictures. the first screen shot is the one of the message I get when I try to access my pictures. the second screen shot is of the two note pads on desktop and I noticed when I looked into my pictures when I clicked on start and went into pictures that way that these notepad things are in there tol
     

    Attached Files:

  4. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Just-Me,

    These are nothing to worry, they are hidden system files
    Some of the tools we use will alter the 'Hidden Files' setting on your system so that the tool has full access to everything.
    It's easy to change this back and hide those files again:

    Click on Start ... Control Panel
    Click on the Appearance and Personalization link .
    Click on Folder Options.
    Click on the View tab.
    Then under Hidden Files and Folders.....Make sure there's a tick against.. Do not show hidden files and folders
    Then click Apply and then Ok.

    32eb71268d9aeac14687248c42e93113.png

    I normally explain how to remove them all when we are cleaning up at the end.

    Yes they are basically the same.
    I prefer TFC as you only have the one button to press...... it will clean out everything including all the browsers in one go.
    It's entirely up to you which you want to use.
    If you want to remove TFC, just right click on the icon and select delete. (it doesn't install to the system)

    This is an interesting one.
    None of the tools or fixes we used would have done this.
    Look at the path to your Picture folder ... at the top:
    and compare this to the path in the message:

    3208f76db6d434cedc4bfde74acd07f9.jpg

    Someone has moved your Picture folder or added a shortcut to it and the default path has subsequently been changed.

    Look at the screenshot of mine:

    0da16c763bf6fcfe7c1f93a913604f99.png

    can you see how yours and mine differ?

    Moving the folder to the correct location should rectify the problem.
    The Picture folder shouldn't be in the My Documents folder
     
  5. Just-Me

    Just-Me Registered Members

    Joined:
    Mar 2, 2014
    Messages:
    117
    Operating System:
    Windows 7
    ok I have my pictures in the correct spot. I guess it did that when I did the format..not sure. no one else uses this laptop except for me. I have an acct for hubby, but is only so I can put his music on his ipod and not have to his music in with my itunes.

    so now that this is done...machine is running fine.
    so I will keep the TFC since its much easier to use and will delete the ATF.

    now if there is nothing else for me to do can you plz tell me how I should delete the programs off of my desktop that we used
    thank you
     
  6. starbuck

    starbuck Rest In Peace Pete Administrator

    Joined:
    Sep 26, 2009
    Messages:
    3,830
    Location:
    Midlands, UK
    Operating System:
    Windows 10
    CPU:
    AMD Athlon II x2 250 Processor 3.00GHz
    Memory:
    8gb DDR3
    Hard Drive:
    500gb SATA
    Graphics Card:
    ASUS GeForce GTX 960 2gb
    Power Supply:
    650w PowerCool X-Viper
    Hi Just-Me,

    Glad to hear that everything seems ok now.

    Step 1
    Restart MBAM.
    Click on the Quarantine tab

    b98d8f9bf07306db6b7853c64ae04fae.png

    If there are items in quarantine.....
    Make sure everything is selected and then click Delete All.
    Close MBAM.


    Step 2
    Double click on AdwCleaner.exe to run the tool again.
    • Click on the Uninstall button.
    • Click Yes when asked are you sure you want to uninstall.
    • Both AdwCleaner.exe, its folder and all logs will be removed.

    JRT and Frst can now be removed also.
    Right click on the Desktop icon for each program and select delete.
    You can also remove any files/reports relating to these programs from the Desktop as well.
    There is also a folder at C:\Frst that can be deleted as well.

    Step 3
    Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

    The easiest and safest way to do this is:
    • Go to Start > Programs > Accessories > System Tools and click "System Restore".
    • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the Restore Point a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
    • Then go to Start > Run and type: Cleanmgr
    • Click "OK".
    • Select the drive for cleaning then click OK (usually 'C' drive)
    • Click the "More Options" Tab.
    • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.

    Note:
    By default, Windows Vista does not have the "Run" command on the start menu. It's easy to get this back.

    1. Open the start menu.
    2. Right click on a non-icon area and select "Properties".
    3. Press the "Customize" button.
    4. Scroll down and find the "Run command" checkbox.
    5. Check it and press OK.
    6. Press OK.

    You now have your run command on the start menu.


    To find out how you may have been infected....read this topic:
    How did i get infected?


    Glad I was able to help.

    Safe surfing. 200636f9a90a19cb85ecf0ba93831af6.gif
     

Share This Page