Author Topic: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled  (Read 7001 times)

0 Members and 1 Guest are viewing this topic.

Offline Notremos58

  • Bronze Member
  • Posts: 35
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #60 on: May 09, 2011, 05:27:11 PM »
Hi Kevin,

Yes I am still with you.  I have transferred a lot of my media onto an external drive. I also ghosted my hard drive to give mysefl some pice of mind.


Mcaffess scan seem to be horrendously slow. I am doing a full scan and so far I am at 75% and it has been running 28 hours. I have been waiting for the scan to finish before taking further action.

Apart from the fixes you last gave me are ther any other things I need to be doing. TMy laptop seem to be firing on all cylinders at the moment - apart from this slow scan.

Rick

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #61 on: May 09, 2011, 09:51:49 PM »
Hiya Rick,

Thanks for the update, lets wait until the McAfee scan finishes and see what it identifies. Post the log it produces and list any issues that remain.
We still need to clean up the tools we have used, also update Java and Adobe. We`ll do that as soon a your system is back to normal....

Thanks,

Kevin













Offline Notremos58

  • Bronze Member
  • Posts: 35
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #62 on: May 10, 2011, 06:56:54 PM »
Hi Kevin.

THe mcafee scan is completed and no threats or issues were found. (Apart from some tracking cookies). I couldn;t find a printable log file.

I don;t have any other additionals issues now.

Rick

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #63 on: May 10, 2011, 11:46:29 PM »
Hiya Rick,

Good to hear the AV scan came back clean, OK continue as follows :-

Step 1

Remove Combofix now that we're done with it
  • Please press the Windows Key and R on your keyboard. This will bring up the Run... command.
  • Now type in Combofix /Uninstall in the runbox and click OK. (Notice the space between the "x" and "/")


  • Please follow the prompts to uninstall Combofix.
  • You will then recieve a message saying Combofix was uninstalled successfully once it's done uninstalling itself.
The above procedure will delete the following:
  • ComboFix and its associated files and folders.
  • VundoFix backups, if present
  • The C:_OtMoveIt folder, if present
  • Reset the clock settings.
  • Hide file extensions, if required.
  • Hide System/Hidden files, if required.
  • Reset System Restore.

It is very important that you get a successful uninstall because of the extra functions done at the same time, let me know if this does not happen.

Step 2

  • Download OTC by OldTimer and save it to your desktop. Alternative mirror
  • Double click icon to start the program.
    If you are using Vista or Windows 7, please right-click and choose run as administrator
  • Then Click the big button.
  • You will get a prompt saying "Begining Cleanup Process". Please select Yes.
  • Restart your computer when prompted.
  • This will remove tools we have used and itself. Any tools/logs remaining on the Desktop can be deleted.

Step 3

Your Adobe Acrobat Reader is out of date. Older versions are vulnerable to attack and exploitation.

Please go to the link below to update.

Adobe Reader Untick the Free McAfeeŽ Security Scan Plus (optional) unless you want it.

Step 4

You are using an old version of Java. Sun's Java is sometimes updated in order to eliminate the exploitation of vulnerabilities in an existing version.
For this reason, it's extremely important that you keep the program up to date, and also remove the older more vulnerable versions from your system.
The most current version of Sun Java is: Java Runtime Environment Version 6 Update 25.

  • Go to Sun Java
  • Select Windows 7/XP/Vista/2000/2003/2008 If using 64 bit OS Select Information about the 64-bit Java plug-in and follow prompts
  • Install the new version by running the newly-downloaded file with the java icon which will be at your desktop, and follow the on-screen instructions.
  • Reboot your computer

Step 5

Download and scan with CCleaner

1. Use either one of the two free links below the Premium version.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 24 hours"
3. Then select the items you wish to clean up.

In the Windows Tab:
 
  • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
       
  • Clean all the entries in the "Windows Explorer" section.
       
  • Clean all entries in the "System" section.
       
  • Clean all entries in the "Advanced" section.
       
  • Clean any others that you choose.
       
  • Make sure "Wipe free space" is unticked, this will dramatically increase scan time if selected.
In the Applications Tab:
 
  • Clean all except cookies in the Firefox/Mozilla section if you use it.
         
  • Clean all in the Opera section if you use it.
         
  • Clean Sun Java in the Internet Section.
         
  • Clean any others that you choose.     
4. Click the "Run Cleaner" button.
5. A pop up box will appear advising this process will permanently delete files from your system.
6. Click "OK" and it will scan and clean your system.
7. Click "exit" when done.

CCleaner is an excellent Utility and well worth keeping, bottom left hand corner of main interface is link "Online Help" use that link to get the full instructions for this very handy application.

Let me know if the above steps complete OK, also if any specific issues remain...

Kevin

Offline Notremos58

  • Bronze Member
  • Posts: 35
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #64 on: May 11, 2011, 05:10:48 AM »
All good thanks Kevin.


Rick

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #65 on: May 11, 2011, 08:33:31 AM »
Hiya Rick.

Good to hear all completed OK, Here are some tips to reduce the potential for malware infection in the future:

Make proper use of your antivirus and firewall

Antivirus and Firewall programs are integral to your computer security. However, just having them installed isn't enough. The definitions of these programs are frequently updated to detect the latest malware, if you don't keep up with these updates then you'll be vulnerable to infection. Many antivirus and firewall programs have automatic update features, make use of those if you can. If your program doesn't, then get in the habit of routinely performing manual updates, because it's important.

You should keep your antivirus and firewall guard enabled at all times, NEVER turn them off unless there's a specific reason to do so. Also, regularly performing a full system scan with your antivirus program is a good idea to make sure you're system remains clean. Once a week should be adequate. You can set the scan to run during a time when you don't plan to use the computer and just leave it to complete on its own.

Install and use WinPatrol  This will inform you of any attempted unauthorized changes to your system.

WinPatrol features explained Here

You will have several programs installed, these maybe outdated and vulnerable to exploits also. To be certain, please run the free online scan by Secunia, available Here   Before clicking the Start scan  button, please check the box for the option Enable thorough system inspection. Just below the "Scan Options:" section, you'll see the status of what's currently processing....
...when the scan completes, the message "Detection completed successfully" will appear in the Programs/Result section. For each problem detected, Secunia will offer a "Solution" option. Please follow those instructions to download updated versions of the programs as recommended by Secunia.


Use a safer web browser

Internet Explorer is not the most secure tool for browsing the web. It has been known to be very susceptible to infection, and there are a few good free alternatives:
 
Firefox,

Opera, and

Chrome.
 
All of these are excellent faster, safer, more powerful and functional free alternatives to Internet Explorer. It's definitely worth the short period of adjustment to start using one of these. If you wish to continue using Internet Explorer, it would be a good idea to follow the tutorial HERE which will help you to make IE MUCH safer.

These browser add-ons will help to make your browser safer:

Web of Trust warns you about risky websites that try to scam visitors, deliver malware or send spam. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous ones:

Available for Firefox and Internet Explorer.

Green to go,
Yellow for caution, and
Red to stop.


Available for Firefox only. NoScript helps to block malicious scripts and in general gives you much better control over what types of things webpages can do to your computer while you're browsing.

These are just a couple of the most popular add-ons, if you're interested in more, take a look at THIS article.

Here a couple of links by two security experts that will give some excellent tips and advice.

So how did I get infected in the first place by Tony Klein

How to prevent Malware by Miekiemoes

Finally this link HERE will give a comprehensive upto date list of free Security programs. To include - Antivirus, Antispyware, Firewall, Antimalware, Online scanners and rescue CD`s.

Don`t forget, the best form of defense is common sense. If you don`t recognize it, don`t open it. If something looks to good to be true, then it aint.

It was a pleasure to work with you; take care,

Kevin

Offline kevinf80

  • Malware Removal Staff
  • Diamond Member
  • Posts: 6366
Re: [Resolved K]PC Only works in Safe Mode - Admin Disable - AV Disabled
« Reply #66 on: May 13, 2011, 01:39:31 AM »
Since this issue appears to be resolved  the topic has been closed. Glad we could help. :t 

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

The fixes and advice in this thread are for this System only. Do not apply the instructions from this thread to your own System. Please start a new thread describing your issue and someone will be along to assist you.