Forum Home
Press F1
 
Thread ID: 111357 2010-07-23 14:12:00 the infamous blue screen of death bigamzz (15898) Press F1
Post ID Timestamp Content User
1121740 2010-07-23 15:18:00 also how do i disable system restore? bigamzz (15898)
1121741 2010-07-23 15:24:00 Well you can keep Avira if you want, but uninstall Panda and Nortons / Symantec's program. If the my computer icon is on the desktop, right mouse on it / properties. Go to the system restore tab, untick it, then OK

Then tick the entries in the log / tick fix checked. Then the rest
Speedy Gonzales (78)
1121742 2010-07-23 15:30:00 right i ticked turn off system restore on all drives but im still having a problem removing the panda anti virus it wont let me remove it from add or remove program sectiion it just does nothing when i click uninstall....and i did the thing in hijackthis before turning off system restore i hope this wont effect it in any way... bigamzz (15898)
1121743 2010-07-23 15:33:00 That should be OK. This is normal windows you're in now right?

Try Panda's uninstall tool www.pandasecurity.com Which is here support.pandasecurity.com

Use Nortons Removal tool, which is here

www.symantec.com
Speedy Gonzales (78)
1121744 2010-07-23 16:47:00 Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org

Database version: 4340

Windows 5.1.2600 Service Pack 2
Internet Explorer 8.0.6001.18702

23/07/2010 16:44:01
mbam-log-2010-07-23 (16-44-01).txt

Scan type: Full scan (C:\|E:\|)
Objects scanned: 191031
Time elapsed: 1 hour(s), 13 minute(s), 27 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 6
Registry Values Infected: 3
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 7

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Ext\Stats\{549b5ca7-4a86-11d7-a4df-000874180bb3} (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_CLASSES_ROOT\WR (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Spyware Cleaner (Rogue.SpywareCleaner) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Enum\R oot\LEGACY_FMTR (Rogue.Multiple) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Servic es\core (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Servic es\SpywareCleanerService (Rogue.SpywareCleaner) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Products\compname (Rogue.SpyGuard) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\prodname (Rogue.PCVirusless) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Products\rdomain (Rogue.PCVirusless) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CLASSES_ROOT\regfile\shell\open\command\(defa ult) (Broken.OpenCommand) -> Bad: ("%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:
C:\WINDOWS\system32\ClickToFindandFixErrors_Intl.i co (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\netstat.com (Worm.Alcra) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\taskkill.com (Worm.P2P) -> Quarantined and deleted successfully.
C:\WINDOWS\hosts (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\wr.txt (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.cache.dsk (Rootkit.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\drivers\core.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
bigamzz (15898)
1121745 2010-07-23 16:59:00 also since using hijackthis earlier my avira anti virus is not showing up on the toolbar (bottom right) but when i click onto it on desktop it says anti virus is enabled...is my computer still protected? bigamzz (15898)
1121746 2010-07-23 20:12:00 irql not less or equal 0x0000000a
....the only thing i can think of is that i added 2 512mb ram sticks

Most of the time this is a driver error. BUT. It can also be RAM, test it.
pctek (84)
1121747 2010-07-23 22:31:00 Is it better now? Look in control panel / security. What does it say for the anti-virus?? Speedy Gonzales (78)
1121748 2010-07-23 23:04:00 it says something about security center being unavailable....and not had any problems so far but its usually my first boot up of the day that it crashes bigamzz (15898)
1121749 2010-07-23 23:09:00 Ok. Get trojan remover www.simplysup.com (pressf1.co.nz)

Update it then click on scan. Then select all the options, under the utilities menu. Whatever it finds, remove it then reboot. Then see if security center works
Speedy Gonzales (78)
1 2 3 4 5