View Single Post
Old 08-11-2008, 06:54 PM   #8 (permalink)
chemist
Moderator, Analyst, Security Team; Rangemaster, TSF Academy
 
Join Date: Oct 2007
Location: Georgia
Posts: 10,286
OS: XP SP3


Re: Trojan.Win32.Monder and variants - Automatic Updates Can't Be Turned on, PC runs

Hello MovieGuru. Do not fret. The Panda log may look bad, but we took care of the bad stuff.

Quote:
So far, everything is running smoothly. PC is back to normal speed, Automatic updates are back and operational, Internet Explorer is browsing normally, with no pop-ups in sight.
Your Panda log is actually fairly clean.

Most of it is in old system restore points and the zip file we uploaded. The files on your L: drive are likely false positives. Is drive L: a Western Digital drive? Except for your cookies, there are a couple adware entries(not trojans).

------------------------------------------------------

Delete [4]-Submit_2008-08-11@0.50.zip from your desktop.

Delete the following Folder if it still exists:

c:\program files\common files\whenu

------------------------------------------------------

Open Notepad and copy/paste the entire contents of the codebox below into Notepad (don't forget to copy and paste REGEDIT4):

Code:
REGEDIT4

[-hkey_local_machine\software\classes\wuse.1]
Save the file as delete.reg and choose to Save as type: - All Files then close the Notepad file.
It should look like this:

Double-click on delete.reg and choose Yes to merge/add it to the registry. You may delete the file afterwards.

------------------------------------------------------

Let's get rid of your cookies. You will want to keep this useful utility to periodically clean out all the junk from your computer.

Please download ATF-Cleaner by Atribune and Save it to your Desktop.
This program is for XP and Windows 2000 only
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.
If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
Click Exit on the Main menu to close the program.
For Technical Support, double-click the e-mail address located at the bottom of each menu.

------------------------------------------------------

If you would feel more comfortable, do another Panda scan and post the log. The old restore points will still show up because we will remove those when we uninstall ComboFix.
__________________
Our help is free but please donate

Proud member of ASAP
Proud member of UNITE
chemist is offline