This thread's last reply is from March 17, 2009, 11:20 PM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Many many thanks for your help with this problem, The P.C seems to be running a lot better now thanks to all your instructions and tools you told me to use.
I will slowly digest what you have written about the extra bits and pieces for keeping my system clean etc. I will certainly join the complaints forum although what i'd like to do to the people responsible may not be suitable for the general members to read!!!!!
John, should i now uninstal combofix, atf cleaner, malewarebytes or should i leave them on my P.C?
Point taken about internet explorer. I do have firefox installed on the P.C and shall endevour to use it from now on.
Thanks again for all your help. Without people like yourself, myself and many others i suspect would be in grave trouble with P.C problems.
I will slowly digest what you have written about the extra bits and pieces for keeping my system clean etc.
Alright, the topic will be moved to another forum but the URL/address will stay the same so you may want to bookmark this topic.
I will certainly join the complaints forum although what i'd like to do to the people responsible may not be suitable for the general members to read!!!!!
Everybody who comes there feels the same Please keep it nice.
John, should i now uninstal combofix, atf cleaner, malewarebytes or should i leave them on my P.C?
The first blue header in my last post called 'uninstall tools' will take care of dangerous tools like ComboFix. In the 'General cleanup' link I have given there is also a little about ATF Cleaner, so you can keep it for regular cleanup of temporary files if you want to. MalwareBytes' Anti-Malware is a nice program to keep for a regular scan. It finds a lot and is very user-friendly.
Please let me know that you have read this and ask any questions you still have.
Regards
Steve
P.S I have not had one instance since you cleaned my P.C of it refusing to restart so it must have been to do with maleware that you removed.
I have a problem in that i can't uninstall combofix. I typed it in the run command as you said and it says "can't find combofix". Any ideas?
The icon has disappeared from the desktop and a search reveals nothing found.
I ran the OTCleanit as you advised It rebooted the p.c but atf cleaner and malewarebytes were still there. I have manually deleted them and done a search to check if they were still on the system but it appears they have been deleted sucessfully.
I have a problem in that i can't uninstall combofix. I typed it in the run command as you said and it says "can't find combofix". Any ideas?
I guess you ran OTCleanUp first, which deletes the ComboFix.exe which was on your desktop and now you cannot remove the rest of ComboFix anymore because the main thing is already gone.
Please download ComboFix from one of these locations: Link 1 Link 2 Link 3
Then save it to your desktop. This is very important. Now run ComboFix /u from the Run box. Afterwards you will probably need to remove the ComboFix.exe on your desktop manually. Just right-click and delete it.
Please let me know you have read this and also ask anymore questions.
I've done what you said to the letter. It keeps putting a warning box up "cannot find ComboFix/u" Any ideas what the problem is? The combofix icon is on the desktop (i haven't installed it just downloaded it)
Is there anything else i should be doing to get rid of it like unticking the show hidden fikles etc as you told me to do in an nearlier post when we were running the scans.
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\UID (Malware.Trace) -> No action taken.
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: c:\windows.0\system32\twext.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Backdoor.Bot) -> Data: system32\twext.exe -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Hijack.UserInit) -> Bad: (C:\WINDOWS.0\system32\userinit.exe,C:\WINDOWS.0\system32\twext.exe,) Good: (userinit.exe) -> No action taken.
Folders Infected:
C:\WINDOWS.0\system32\twain_32 (Backdoor.Bot) -> No action taken.
Files Infected:
C:\WINDOWS.0\system32\twain_32\local.ds (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twain_32\user.ds (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twain_32\user.ds.cla (Backdoor.Bot) -> No action taken.
C:\WINDOWS.0\system32\twext.exe (Backdoor.Bot) -> No action taken.
BTW i have deleted all as they were checkmarked.
It does not say that you deleted them. Please make sure you did. Then reboot your computer a couple of times and run another scan. It is really strange that it came back and I want to be sure your computer is completely clean.
This is a dual boot computer, right? Do you ever use the other operating system/partition?
Sorry, didn't explain fully in my last post. Saved the log before i deleted all the checked items.
It did say after i'd done that to restart my P.C as some of the stuff couldn't be cleaned exept by a restart. Restarted the P.C did a virus scan with eset, scan with superantispyware then did another scan with malwarebytes and all came back with no infections, so it looks like the system is clean.
Sorry for my ignorance but i don't know what you mean by dual boot. The only thing i can think of is that when i boot the P.C up i get a black screen that stays on for about 3 seconds and shows windows twice and recovery consule then it carries on booting up as normal. Must say that screen has only appeared since i installed the recovery consul as advise by one of the peices of software (think it may have been Combofix) that you had me run in the beginning.
I've heard the term partitian before and know it's something to do with the hard drive, other than that i just boot the P.C up and use it. The file system is NTFS if that's any use.
Sorry, didn't explain fully in my last post. Saved the log before i deleted all the checked items.
It did say after i'd done that to restart my P.C as some of the stuff couldn't be cleaned exept by a restart. Restarted the P.C did a virus scan with eset, scan with superantispyware then did another scan with malwarebytes and all came back with no infections, so it looks like the system is clean.
Alright, should be good then.
Sorry for my ignorance but i don't know what you mean by dual boot. The only thing i can think of is that when i boot the P.C up i get a black screen that stays on for about 3 seconds and shows windows twice and recovery consule then it carries on booting up as normal. Must say that screen has only appeared since i installed the recovery consul as advise by one of the peices of software (think it may have been Combofix) that you had me run in the beginning.
It is not about that screen (which is so you can use the Recovery Console if ever your system would become unable to boot). It is about the two Windows versions showing up. It means that once Windows was installed and then it was installed another time but then on C:\Windows.0 instead of regularly C:\Windows. But if you never use that old version it does not matter.
Please let me know when you read this and if the topic can be closed.
No ads, no affiliate links — generated on request from this thread's own
archived content, not written by forum staff. Never run a scan/removal tool
as a self-service step if the original thread describes it being done under
a helper's direct supervision, and don't include your name, email, or other
personal details in a follow-up question. See our privacy page
for details on how this works.