And I can't move it to the chest as it says it "can't find the path specified"can you attach a screenshot of the detection
Hi Pondus ![]()
attached! this is if I try to delete, if I try to move to chest I get the can’t find path message
Open the virus chest click and hold the bar as shown then move your mouse to the right. That should extend the filepath so that the full location can be read
hey essexboy
the location was Google Desktop - which I deleted yesterday.
attached jpg!
Try this
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: c:\documents and settings\local settings\application data\google\google desktop EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
thanks essexboy!
attached log
I made a bobo and transcribed the path wrong… Sorry
CAUTION : This fix is only valid for this specific machine, using it on another may break your computer
Open notepad and copy/paste the text in the quotebox below into it:
CreateRestorePoint: CreateRestorePoint: c:\documents and settings\user1\local settings\application data\google\google desktop EmptyTemp: CMD: bitsadmin /reset /allusers EmptyTemp: CMD: bitsadmin /reset /allusers
Save this as fixlist.txt, in the same location as FRST.exe
https://dl.dropboxusercontent.com/u/73555776/FRSTfix.JPG
Run FRST and press Fix
On completion a log will be generated please post that
haha you’re helping me, so you’re forgiven! ;D
log attached!
c:\documents and settings\user1\local settings\application data\google\google desktop => Moved successfully. Tada
How is the computer behaving now ?
yay! so if I go into my scan results I can now delete the Trojan from the list?? or will I have to do another reboot scan??
browser is not as fast as it was before but it’s good!
so has the Trojan been removed completely?
Yes the one Avast was reporting should now be history
Any further problems ?
it’s still in the scan history - will I need to reboot?
browser is not as fast as it was earlier (maybe something to do with system restore?) but it’s all good, at least I can open pages. ;D
I’m still getting a slight freeze when opening files, but nothing major.
should I delete those 3 programs now - ComboFix, AdwCleaner and FRST? and all the logs? and what about the recovery disk?
thank you so much for helping me! ;D
EDIT: ohhh essexboy, now it’s my turn to make a bobo! I’m so stupid…I think we got our wires crossed. Did you think I meant the Trojan was in the virus chest? I meant it was still showing up in the scan history. :-[ Ohh dear…those can’t be deleted can they? Oops…so does that mean we didn’t have to do those 2 system restores? Ohh I’m so stupid and embarrassed! :-[
I’ve attached a jpg of what I meant! I’m so sorry. :-[ :-[
it’s still odd though that when I try to delete it, it says “action postponed until next reboot” - or is it? :-[
Ah that is the history
Open Avast go to Settings > General > Maintenance and clear the scan history from there … Screenshot right at the end I will make another post on how to stop recovery console showing ![]()
Subject to no further problems ![]()
I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems
Now the best part of the day ----- Your log now appears clean ![]()
A good workman always cleans up after himself so…The following will implement some cleanup procedures as well as reset System Restore points:
Remove Combofix
Click Start then Run.
On Windows7 or Vista you may use Start Search field if Run is not available.
In the box copy/paste the following command:
ComboFix /Uninstall
Note that there is a space between " ComboFix " and " /Uninstall " .
Then click OK (or press Enter ).
Wait for the uninstall process to complete.
Remove tools
Download and run Delfix
https://dl.dropboxusercontent.com/u/73555776/delfix.JPG
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
CryptoPrevent install this programme to lock down and prevent crypto ransome ware
https://dl.dropboxusercontent.com/u/73555776/CryptoPrevent.JPG
Update and run weekly to keep your system clean
Click on the link above to be taken to Unchecky.com
click the very large Download button.
click Save
Click Open folder
Right click on the Unchecky_setup and choose to Run as Administrator
Once open click the Install button.
Then click on Finish
Unchecky is now installed and will help you keep unwanted check boxes unchecked, this is a fire and forget programme ![]()
It is critical to have both a firewall and anti virus to protect your system and to keep them updated.
To learn more about how to protect yourself while on the internet read this little guide Best security practices Keep safe ![]()
To remove the recovery console from startup boot screen
Go Start > Right click My Computer and select Properties
On the dialogue that opens select the Advanced tab
Under Start up and recovery select Settings
Remove the tick from the Time to display operating systems box
OK out and you are done
hey essexboy! ![]()
thanks for getting back to me, still can’t believe how stupid I was yesterday, haha! oh dear well I did say I was a total dummy at this pc tech stuff! ;D
ok so is it safe to have CryptoPrevent when I have Avast and MBAM? there won’t be any conflict?
No conflict at all … I use them ![]()
Let me know how it is once you have done all of the above
hey essexboy ![]()
sorry for not getting back to you sooner, had internet issues yesterday! I swear technology hates me!
things seem ok! browser is good, still getting a slight delay (freeze) but nothing that makes me want to scream haha! files opening as normal! so yeah I’m a happy bunny! ![]()
haven’t downloaded crypto yet, but uninstalled everything you told me to (although when I uninstalled ComboFix, it ran, thanked me for installing (??) told me to turn off antivirus and then uninstalled and generated a log file - but I’ve gone into documents and the file is gone, so either I accidentally deleted it or I’m looking in the wrong place!) I hope you didn’t need it for anything??
fingers crossed everything is back to normal! If I have anymore issues I’ll get back to you, otherwise (and I know its rude to type in caps but I feel I must) THANK YOU SO SO MUCH! you’re seriously the best, don’t know what I would have done without your help! so grateful! ;D
EDIT: hey essexboy! ok, so I had to update iTunes and Avast found 2 threats while I was doing it - GEARDIFx.exe They’re both in the chest, but is this bad??
I’ve attached 2 jpgs
Avast is recommending a boot-time scan, but I don’t know if this will delete whats in the chest! should I wait until you’ve looked at this? :-\
EDIT 2: another one just came up!
I have no idea what this chat2way service is (!)
Intriguing geardifx.exe is part of Norton or Nero
GEARDIFx.exe belongs to the CD/DVD authoring software that Norton 360 uses to backup to CDs and DVDs.
So I would call that a false positive. Where did you download iTunes from ?
The other one is part of citrix… Do you use that ?
hmm, Nero is on my PC but I think I’ve used it once? :-\
opened iTunes, got the update message and just updated like I always have. :-\
I have no idea what Citrix is! :o
should I just leave them in the chest? or delete…?
In that case you can manually delete those two folders
The one with gear in it is where iTunes unpacks the data so mayhap that has a cd/dvd writing capability now