Welcome to MalwareRemoval.com,
What if we told you that you could get malware removal help from experts, and that it was 100% free? MalwareRemoval.com provides free support for people with infected computers. Our help, and the tools we use are always 100% free. No hidden catch. We simply enjoy helping others. You enjoy a clean, safe computer.

Malware Removal Instructions

Please Help!!!

MalwareRemoval.com provides free support for people with infected computers. Using plain language that anyone can understand, our community of volunteer experts will walk you through each step.

Re: Please Help!!!

Unread postby Dakeyras » April 3rd, 2010, 11:13 am

Hi. :)

Custom OTM Script:

  • Double-click OTM to start the program.
  • Copy the lines from the codebox to the clipboard by highlighting ALL of them and pressing CTRL + C (or, after highlighting, right-click and choose Copy):
Code: Select all
:Processes

:Files
C:\Program Files\YesTrader
C:\Documents and Settings\Administrator\My Documents\LimeWire

:Commands
[EmptyTemp]
[Start Explorer]
[Reboot]
  • Return to OTM, right-click in the "Paste instructions for items to be moved" window (under the yellow bar) and choose Paste
  • Then click the red MoveIt! button.
  • Copy everything in the Results window (under the green bar) to the clipboard by highlighting ALL of it and pressing CTRL + C (or, after highlighting, right-click and choose Copy), and paste it into your next response.
  • If OTM asks to reboot your computer, allow it to do so. The report should appear in Notepad after the reboot.
  • Close OTM.


When completed the above, please post back the following:

  • How is your computer performing now? Any problems encountered and or any further symptoms?
  • OTM Log.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra
Advertisement
Register to Remove

Re: Please Help!!!

Unread postby MatthewV » April 4th, 2010, 1:24 am

Hi, this machine is still running properly and I've encountered no problems so far during the removal process.

Here is the OTM log...

All processes killed
========== PROCESSES ==========
========== FILES ==========
C:\Program Files\YesTrader\SierraChart\Trading folder moved successfully.
C:\Program Files\YesTrader\SierraChart\pNotepad\taggers folder moved successfully.
C:\Program Files\YesTrader\SierraChart\pNotepad\schemes folder moved successfully.
C:\Program Files\YesTrader\SierraChart\pNotepad\Microsoft.VC80.CRT folder moved successfully.
C:\Program Files\YesTrader\SierraChart\pNotepad\clips folder moved successfully.
C:\Program Files\YesTrader\SierraChart\pNotepad folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp\plugins\NPPTextFX folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp\plugins\doc folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp\plugins\Config folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp\plugins\APIs folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp\plugins folder moved successfully.
C:\Program Files\YesTrader\SierraChart\npp folder moved successfully.
C:\Program Files\YesTrader\SierraChart\language folder moved successfully.
C:\Program Files\YesTrader\SierraChart\data folder moved successfully.
C:\Program Files\YesTrader\SierraChart\ACS_Source folder moved successfully.
C:\Program Files\YesTrader\SierraChart folder moved successfully.
C:\Program Files\YesTrader\RemoteAssist folder moved successfully.
C:\Program Files\YesTrader\Logs folder moved successfully.
C:\Program Files\YesTrader folder moved successfully.
C:\Documents and Settings\Administrator\My Documents\LimeWire\Store Purchased folder moved successfully.
C:\Documents and Settings\Administrator\My Documents\LimeWire\Shared folder moved successfully.
C:\Documents and Settings\Administrator\My Documents\LimeWire\Saved folder moved successfully.
C:\Documents and Settings\Administrator\My Documents\LimeWire\Incomplete folder moved successfully.
C:\Documents and Settings\Administrator\My Documents\LimeWire folder moved successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Administrator
->Temp folder emptied: 106702560 bytes
->Temporary Internet Files folder emptied: 94934471 bytes
->Java cache emptied: 131275 bytes
->Flash cache emptied: 3090 bytes

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: LocalService
->Temp folder emptied: 65984 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Java cache emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 82499 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes
%systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 193.00 mb


OTM by OldTimer - Version 3.1.10.1 log created on 04032010_221710

Files moved on Reboot...
C:\WINDOWS\temp\Perflib_Perfdata_bcc.dat moved successfully.

Registry entries deleted on Reboot...
MatthewV
Regular Member
 
Posts: 27
Joined: March 3rd, 2010, 10:53 pm

Re: Please Help!!!

Unread postby Dakeyras » April 4th, 2010, 3:36 pm

Hi. :)

Congratulations your computer now appears to be malware free!

Disclaimer: Given the nature of the infections that were present on the machine, I give no guarantees about the security of this computer and have to the best of my abilities tried to both identify and eradicate all malware.

Next:

Now I have some tasks for your good self to carry out as part of a clean up process and some advice about online safety.

Importance of Regular System Maintenance:

I advice you read both of the below listed topics as this will go a long way to keeping your Computer performing well.
Help! My computer is slow!

Also so is this:

What to do if your Computer is running slowly

Uninstall ComboFix:

  • Click on Start >> Run...
  • Now type in ComboFix /Uninstall into the and click OK.
  • Note the space between the X and the /Uninstall, it needs to be there.
  • Image

Clean up with OTM:

  • Double-click OTM to start the program.
  • Close all other programs apart from OTM as this step will require a reboot
  • On the OTM main screen, press the CleanUp! button
  • Say Yes to the prompt and then allow the program to reboot your computer.

The above process should clean up and remove the vast majority of scanners used and logs created etc.

Any left over merely delete yourself and empty the Recycle Bin.

Now some advice for on-line safety:

Malwarebyte's Anti-Malware:

This is a excellent application and I advise you keep this installed. Check for updates and run a scan once a week.

Other installed security software:

Your presently installed security application, AVG automatically checks for updates and downloads/installs them with every system reboot and or periodically if the machine is left running providing a internet connection is active.

I advise you also run a complete scan with this also once per week.

Erunt:

Emergency Recovery Utility NT, I advice you keep this installed as a means to keep a complete backup of your registry and restore it when needed.

Myself I would actually create a new back up once per week as this along with System Restore may prove to be invaluable if something unforeseen occurs!

Keep your system updated:

Microsoft releases patches for Windows and other products regularly:


Avoid Peer to Peer software:

P2P may be a great way to get lots of seemingly freeware, but it is a great way to get infected as well. There's no way to tell if the file being shared is infected. Worse still, some worms spread via P2P networks, infecting you as well. My advice avoid these types of software applications.

Hosts File:

A Hosts file is like a phone book. You look up someone's name in the phone book before calling him/her. Similarly, your computer will look up the website's IP address before you can view the website.

Hosts file will replace your current Hosts file with another one containing well-known advertisement sites, spyware sites and other bad sites. This new Hosts file will protect you by re-directing these bad sites to 127.0.0.1.

Here are some Hosts files:


Only use one of the above.

Optional update:

There is a new service pack for XP, namely SP3. I advise you download/install this as it will increase the security side of your system.

Download can be found here or the CD ordered for your country here <--scroll down to and click on 'How to obtain Windows XP Service Pack 3 on a CD'

Please read this Microsoft article before actually installing the aforementioned service pack.

Advised Optional Installation:

There is no sign of a software firewall installed on your system. Regardless if using a hardware type and or using the inbuilt Windows Service Pack 2(Or 3 if you upgrade) firewall this is a necessary application as it will also provide outbound protection where as the aforementioned do not.

I highly advise you download ONE of the following firewalls and install it. Restart the computer for changes to take effect.


This article is a excellent resource regarding the aforementioned firewalls: Understanding and Using Firewalls

Finally a educational source:

To learn more about how to protect yourself while on the internet read this article by Tony Klein:

So how did I get infected in the first place?

Some consider this article outdated, personally I still think it bares relevance and the author is well respected in the Anti-Malware community and by myself also!

Any questions? Feel free to ask. if not stay safe!
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra

Re: Please Help!!!

Unread postby Dakeyras » April 5th, 2010, 6:33 pm

As this topic is resolved, this topic is now closed.

We are pleased we could help you resolve your computer's malware issues.

If you would like to make a comment or leave a compliment regarding the help you have received, please see Feedback for Our Helpers - Say "Thanks" Here.
User avatar
Dakeyras
MRU Honors Graduate
MRU Honors Graduate
 
Posts: 8732
Joined: November 21st, 2007, 5:30 am
Location: The Tundra
Advertisement
Register to Remove

Previous

Return to Infected? Virus, malware, adware, ransomware, oh my!



Who is online

Users browsing this forum: No registered users and 30 guests

Contact us:

Advertisements do not imply our endorsement of that product or service. Register to remove all ads. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk. All trademarks are the property of their respective owners.

Member site: UNITE Against Malware