everything is running very slow so I apologize if I’m not getting back to you fast enough! :-[
EDIT hey essexboy, I’m getting this message when I run ComboFix …
I installed it. Hope I’ve done right thing! Now getting a warning:
Unable to create a backup of current registry file C:\WINDOWS\system32\config\SECURITY !
it’s asking me to continue restoration???
Lots of warnings now. Do I click yes for all of them?
I sound like a frantic lunatic haha sorry essexboy! It’s busy
Preparing log report but when it rebooted the screen was
Black (like safe mode?) with 3 options but then it
Started as normal.
OK all malware cleared, now we just need to speed you up a bit
Download to your desktop Mike Lin’s startup control panel https://web.archive.org/web/20131106030702/http://www.mlin.net/StartupCPL.shtml
Download this version Download Startup Control Panel 2.8 (59kb)
Open the zip file by double clicking
Double click the startupcpl file that you now see this will install the programme
Now go to control panel and you will see a startup icon (picture 1)
Double click this and the programme will open
Go to the HKLM Run tab
Right click all entries except Avast and select disable (picture 2 )
Repeat for the HKCU tab
Now reboot your computer
All the changes can be reversed by running startup from the control panel and right click then select enable
Ok, so I’ve uninstalled Google Desktop (hurrah!), checked Avast log and the trojan is still there. Still won’t let me delete it (!) Tried to move it to chest but it said it could not find the path specified.
Should I do an Avast reboot? will that clear it once and for all?
I still haven’t downloaded the last program you’ve advised me too yet! I just wondered if I should reboot first?
also…is there any way that Avast could have been compromised by the trojan? should I delete and reinstall…?
(so many questions, sorry!) :-[
sorry for the delay in getting back to you, bit of a crazy day! :o
ok, so I did the Avast reboot scan and the Trojan is still showing up in the threat section (?), but when I try to delete it from the list it still won’t let me and says “action postponed until next reboot” (!) which I’ve done like 3 times (!) And I can’t move it to the chest as it says it “can’t find the path specified” :-\
Should I be really concerned about this?
has the Trojan definitely been removed?
maybe I should uninstall Avast and reinstall? Would that clear it?
also, did a windows scan and I got this - windows replaced bad clusters in file 38232 of name \DOCUME~1\user1\APPLIC~1\Mozilla\Firefox\Profiles\OGOKWO~1. DEF\WEBApp~1.SQL.
since then, browsers back to normal - a LOT faster! ;D and opening files also much quicker!
So do I need to do the Mike Lin thing you said?
I shall await your instruction!
EDIT: meant to ask you - I deleted Google Earth, Photos Screensaver, picasa, kindle - but there are still files in my documents folder - is it safe to delete them??