We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

DriveCleaner - why?

1356

Comments

  • andyrules
    andyrules Posts: 3,558 Forumite
    Can anyone tell me if I am able to safely use my Ccard online while I have this infection? Thanks
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I would say no


    Download SDFix and save it to your Desktop.

    Double click SDFix.exe and choose Install to extract it to its own folder on the Desktop. Please then reboot your computer in Safe Mode by doing the following :
    • Restart your computer
    • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
    • Instead of Windows loading as normal, the Advanced Options Menu should appear;
    • Select the first option, to run Windows in Safe Mode, then press Enter.
    • Choose your usual account.
    • Open the extracted SDFix folder and double click RunThis.bat to start the script.
    • Type Y to begin the cleanup process.
    • It will remove any Trojan Services or Registry Entries found then prompt you to press any key to Reboot.
    • Press any Key and it will restart the PC.
    • When the PC restarts the Fixtool will run again and complete the removal process then display Finished, press any key to end the script and load your desktop icons.
    • Once the desktop icons load the SDFix report will open on screen and also save into the SDFix folder as Report.txt.
    • Finally copy and paste the contents of the results file Report.txt back onto the forum with a new HijackThis log along with the Vundo report if anything was found and\or removed.
    Ex forum ambassador

    Long term forum member
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    if that fails try this in normal windows mode

    Download combofix.exe
    • Double click combofix.exe & follow the prompts.
    • When finished, it shall produce a log for you. Post that log in your next reply with a new HJT log please.
    Note:
    Do not mouseclick combofix's window whilst it's running. That may cause it to stall.
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    cheers browntoa - am off to do it now. Are my bank details safe do you think?
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    not until it's clean...I'm concerned tha something is stopping the software from doing it's job

    if still no joy from either of these then do a hijackthis log for me

    http://www.tomcoyote.org/hjt/
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    hi browntoa that seemed to go ok, i've got reports from that and smitfraud, nothing from vundo or hijack. Shall I post them?
  • andyrules
    andyrules Posts: 3,558 Forumite
    didnt do the combofix
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    do combo now and then post that and the other logs...

    any sign of it going yet ??
    Ex forum ambassador

    Long term forum member
  • andyrules
    andyrules Posts: 3,558 Forumite
    not sure, it pops up often so I'll soon know! I've put the report thing here, now will do the combo. Cheers for a while..

    SDFix: Version 1.87

    Run by Administrator - 12/06/2007 - 20:51:42.64

    Microsoft Windows XP [Version 5.1.2600]

    Running From: C:\SDFix

    Safe Mode:
    Checking Services:






    Restoring Windows Registry Values
    Restoring Windows Default Hosts File

    Rebooting...


    Normal Mode:
    Checking Files:

    Below files will be copied to Backups folder then removed:

    C:\WINDOWS\system32\winsys.exe - Deleted



    Removing Temp Files...

    ADS Check:

    Checking if ADS is attached to system32 Folder
    C:\WINDOWS\system32
    No streams found.

    Checking if ADS is attached to svchost.exe
    C:\WINDOWS\system32\svchost.exe
    No streams found.

    Checking if ADS is attached to ntoskrnl.exe
    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    Remaining Services:



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    Remaining Files:

    Backups Folder: - C:\SDFix\backups\backups.zip

    Listing Files with Hidden Attributes:

    C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL0087.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL0167.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL1489.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\medium term planning\~WRL3811.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\PLANNING AND OUTCOMES\2006-2007\NEW LITERACY\~WRL0001.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\PLANNING AND OUTCOMES\2006-2007\NUMERACY\~WRL0168.tmp

    Listing User Accounts:

    User accounts for \\HOME-VLXXBPRCM8

    Administrator Dave Guest
    HelpAssistant SUPPORT_388945a0


    Finished

    Rebooting...


    Normal Mode:
    Checking Files:

    No Trojan Files Found




    Removing Temp Files...

    ADS Check:

    Checking if ADS is attached to system32 Folder
    C:\WINDOWS\system32
    No streams found.

    Checking if ADS is attached to svchost.exe
    C:\WINDOWS\system32\svchost.exe
    No streams found.

    Checking if ADS is attached to ntoskrnl.exe
    C:\WINDOWS\system32\ntoskrnl.exe
    No streams found.



    Final Check:

    Remaining Services:



    Authorized Application Key Export:

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]

    [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]

    Remaining Files:

    Backups Folder: - C:\SDFix\backups\backups.zip

    Listing Files with Hidden Attributes:

    C:\Program Files\Common Files\Adobe\ESD\DLMCleanup.exe
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL0087.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL0167.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\~WRL1489.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\medium term planning\~WRL3811.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\PLANNING AND OUTCOMES\2006-2007\NEW LITERACY\~WRL0001.tmp
    C:\Documents and Settings\Dave\My Documents\work docs\PLANNING AND OUTCOMES\2006-2007\NUMERACY\~WRL0168.tmp

    Listing User Accounts:

    User accounts for \\HOME-VLXXBPRCM8

    Administrator Dave Guest
    HelpAssistant SUPPORT_388945a0


    Finished
  • Browntoa
    Browntoa Posts: 49,612 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    runnccleaner to get rid of your temp files

    www.ccleaner.com

    after combofix
    Ex forum ambassador

    Long term forum member
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.5K Banking & Borrowing
  • 253.7K Reduce Debt & Boost Income
  • 454.5K Spending & Discounts
  • 245.5K Work, Benefits & Business
  • 601.5K Mortgages, Homes & Bills
  • 177.6K Life & Family
  • 259.5K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.