Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 93121 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

kraken bobax warning "not removeable" and crash :(


  • This topic is locked This topic is locked
54 replies to this topic

#46 eBayvictim

eBayvictim

    Authentic Member

  • Authentic Member
  • PipPip
  • 107 posts

Posted 03 May 2011 - 05:34 PM

I didn't have to open notepad....it produced this log upon rebooting (is it the correct log?) _______________________ All processes killed ========== PROCESSES ========== ========== REGISTRY ========== Registry key HEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\ deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Leonard Roe ->Temp folder emptied: 315862 bytes ->Temporary Internet Files folder emptied: 100847934 bytes ->Java cache emptied: 382273 bytes ->FireFox cache emptied: 36219662 bytes ->Google Chrome cache emptied: 11303870 bytes ->Flash cache emptied: 19634 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 32902 bytes ->Flash cache emptied: 499 bytes User: NetworkService ->Temp folder emptied: 5898 bytes ->Temporary Internet Files folder emptied: 67 bytes User: Owner %systemdrive% .tmp files removed: 6597 bytes %systemroot% .tmp files removed: 20471 bytes %systemroot%\System32 .tmp files removed: 9455121 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 5389 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temp folder emptied: 0 bytes %systemroot%\system32\config\systemprofile\Local Settings\Temporary Internet Files folder emptied: 33170 bytes RecycleBin emptied: 8876 bytes Total Files Cleaned = 151.00 mb OTM by OldTimer - Version 3.1.17.2 log created on 05032011_192824 Files moved on Reboot... Registry entries deleted on Reboot...

    Advertisements

Register to Remove


#47 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 03 May 2011 - 05:47 PM

Yeppers. Thats it. :thumbup:

Let's cleanup. :woot:

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /Uninstall in the runbox and click OK
  • Note the space between the X and the U, it needs to be there.
The above procedure will:
  • Implement some cleanup procedures.
  • Reset System Restore.

Cleanup

  • Double click on OTM to run it.
  • Click on CleanUp!
  • When done, you will be prompted to restart your computer. Please restart your computer.


Please re-enable any security that was disabled.

You will probably have some files/ logs still on your desktop that we saved there throughout this process. You can go ahead and delete them.


The following is my standard advice for the future. Use what you can and pat yourself on the back for what you're already doing.

Please take time to read Preventing Malware - Tools and Practices for Safe Computing. Very important information for your consideration is contained therein.

I would also suggest you read this:
So how did I get infected in the first place?
by Tony Klein


Also: "How to prevent malware"
by miekiemoes

Please respond back that you understand the above and let me know if you have any questions. Otherwise, this thread will be closed Resolved. :thumbup:
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#48 eBayvictim

eBayvictim

    Authentic Member

  • Authentic Member
  • PipPip
  • 107 posts

Posted 03 May 2011 - 06:02 PM

I will follow your instructions right now....and then report back... As an ebay victim, I do have a paypal account, I'm not broke, but I am a little bent, but I'll still be making a donation You guys deserve more than I can give.....that's for sure :) Back as soon as I am done.....

#49 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 03 May 2011 - 06:06 PM

Donations are completely your call. They are not required nor are they expected. Mothers day is this weekend. Keep your priorities straight and don't put yourself in a bind.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#50 eBayvictim

eBayvictim

    Authentic Member

  • Authentic Member
  • PipPip
  • 107 posts

Posted 03 May 2011 - 06:14 PM

My mom gets her due :) hehe All that you instructed is completed and went fine. May I ask? ............. in your opinion, (and I understand it would be JUST an opinion), is there anything I'm running or using that I'd be better off without? like RUbotted, or maybe one of the browsers, etc etc? just curious for your observations. Thanks

Edited by eBayvictim, 03 May 2011 - 06:17 PM.


#51 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 03 May 2011 - 06:34 PM

eBayvictim,

I'm not a big fan of Trend Micro products in general. They aren't "bad". They're just resource hogs. I don't really know anything about RUbotted. In my never-to-be-humble opinion, you don't need it. Keep your MSSE up to date and supplement it with Malwarebytes'.. It won't run automatically so update it and run it once a week or so. From there... it is pretty much up to you to keep yourself safe by not browsing to questionable sites, not clicking on links in emails, stay away from file sharing sites.... the normal stuff.

Browsers are totally a personal choice. It's "fun" to try out different ones, but most people find they prefer one over the other for various reasons. I typically use FireFox, as much for a couple tools that I use in malware hunting that only run in FireFox, as for anything else. I tried Safari and didn't like it. I've heard good things about IE9, but I don't have any systems with anything newer than XP so I can't run it. Chrome has some good features, and a couple of the tools I use are being reworked to run on it. I'm not sure I can really say that any one browser is better than another.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#52 eBayvictim

eBayvictim

    Authentic Member

  • Authentic Member
  • PipPip
  • 107 posts

Posted 03 May 2011 - 06:39 PM

OK, great.... We're done, but one last question.... Maybe I'm losing my mind, but I could have sworn I saw a link for PayPal donations, and now I can't seem to find it. Please direct me to the proper link which will insure that I am sending to What the tech, and then shut this puppy down :P (as someone used to say on a photo-sharing site I frequent) haha....

#53 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 03 May 2011 - 06:44 PM

Donations. Ignore the "recommended download" ads. They are recommended by Google... not me or this site.

Thank you.

Good luck and be Well! :thumbup:
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

#54 eBayvictim

eBayvictim

    Authentic Member

  • Authentic Member
  • PipPip
  • 107 posts

Posted 03 May 2011 - 06:49 PM

done! and to you as well :)

#55 Tomk

Tomk

    Beguilement Monitor

  • Global Moderator
  • 20,451 posts

Posted 03 May 2011 - 06:56 PM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatth...ed_t106388.html
and start a New Topic.
Tomk
------------------------------------------------------------
Microsoft MVP 2010-2014
 

    Advertisements

Register to Remove

Related Topics



3 user(s) are reading this topic

0 members, 3 guests, 0 anonymous users