Computer Hope

Software => Computer viruses and spyware => Topic started by: !~*:.Pink Floyd.:*~! on August 29, 2008, 08:03:30 PM

Title: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 29, 2008, 08:03:30 PM
Hey I Think I have a virus!
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 29, 2008, 08:15:29 PM
Ill get the logs in In the Mean Time I was browsing And I got linked to a site Called

Doom3.zoy.org

Can I get a report if that site is safe?
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 29, 2008, 10:28:25 PM
http://www.siteadvisor.com/
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 07:16:12 AM
Malware bytes log.

[recovering disk space -- attachment deleted by admin]
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 10:56:10 AM
Run the  Kaspersky Online Scanner (http://www.kaspersky.com/virusscanner)

In Microsoft Windows Vista, you must open the Web browser using the Run as Administrator command. From the Desktop right click the icon to open the browser and choose Run as Administrator.

When the scan is done, in the Scan is complete window, any infection is displayed.
There is no option to clean/disinfect, however, we need to analyze the information on the report.

To obtain the report:
Click on: Save Report As(http://i154.photobucket.com/albums/s258/evilfantasy69/Kas-Savetxt.gif)

Copy and paste the Kaspersky Online Scanner Report in your next reply.

Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 03:43:08 PM
It keeps saying several java virtual machines running in the same process caused an error.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 03:54:26 PM
Run this then try again.

Download  JavaRa (http://www.majorgeeks.com/JavaRa_d5967.html)
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 07:34:32 PM
Run this then try again.

Download  JavaRa (http://www.majorgeeks.com/JavaRa_d5967.html)
  • Unzip the file and open the JavaRa.exe
  • Click Remove Older Versions
  • JavaRa will search for and remove any outdated version of Java and remove any that are found.
  • Exit JavaRa
  • Delete the JavaRa .zip .exe and .html files from the Desktop

K I did that it seems I cant open anything requires java now.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 07:39:17 PM
Maybe it was outdated altogether.

Install the newest version. http://filehippo.com/download_java_runtime/
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 07:46:18 PM
Maybe it was outdated altogether.

Install the newest version. http://filehippo.com/download_java_runtime/

Kk I installin it now.

Does that link update to the latest version?

I couldnt seem to find the new version on the website.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 07:46:50 PM
I tell you when Im done.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 07:47:10 PM
Yep, right here http://filehippo.com/download_java_runtime/download/c28613d7a64f810d2f74797833d9a0f1/
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 07:52:26 PM
Yep, right here http://filehippo.com/download_java_runtime/download/c28613d7a64f810d2f74797833d9a0f1/

Im done updating now what?

http://enigmasand.com/pyro2.html


I tested it bye going thar above meh ^
great fun game bye the way.

It made the game loading speed tons faster.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 07:53:08 PM
See if Kaspersky will run now.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 08:11:34 PM
See if Kaspersky will run now.

yeah It runs but im gonna have to scan tommorrow

So

:x

Stick with me.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 30, 2008, 08:13:11 PM
No worries. (http://smiley.onegreatguy.net/monkey.gif)
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 30, 2008, 08:22:10 PM
No worries. (http://smiley.onegreatguy.net/monkey.gif)

Lmao...

Thanks for helping me with the java update thing.

I should have the kaspersky log sometime around lunch time Eastern time.

Im not gonna be here around 4:00-8:00

Going out to a sushi bar.

So that will be fun.

Thanks for the help though.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 09:25:57 AM
I just found 2 nasties already.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 09:27:56 AM
It seems that auto clicker that never worked was against me not with me.
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 31, 2008, 09:47:32 AM
Log?
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 09:53:07 AM
Log?

Oh its still scanning buddy.

Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 09:53:43 AM
Im gonna get Comodo And kaspersky if that sounds good
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 10:19:21 AM
--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7 REPORT
 Sunday, August 31, 2008
 Operating System: Microsoft Windows XP Professional Service Pack 2 (build 2600)
 Kaspersky Online Scanner 7 version: 7.0.25.0
 Program database last update: Sunday, August 31, 2008 15:31:42
 Records in database: 1172087
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   C:\
   D:\

Scan statistics:
   Files scanned: 62493
   Threat name: 2
   Infected objects: 52
   Suspicious objects: 0
   Duration of the scan: 00:38:09


File name / Threat name / Threats count
C:\Documents and Settings\Charles  Donaldson\Application Data\Sun\Java\Deployment\cache\6.0\25\650d0659-776fb091   Infected: Exploit.Java.Gimsh.a   1
C:\Documents and Settings\Charles  Donaldson\Application Data\Sun\Java\Deployment\cache\javapi\v1.0\jar\jvmimpro.jar-6d00d9f7-5607f171.zip   Infected: Exploit.Java.Gimsh.a   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\MofikiAutoClickerPremium.zip   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 1 for MofikiAutoClickerPremium-1.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 1 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 10 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 11 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 12 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 13 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 14 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 15 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 16 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 17 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 18 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 19 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 2 for MofikiAutoClickerPremium-1.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 2 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 20 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 21 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 22 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 23 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 24 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 25 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 26 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 27 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 28 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 29 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 3 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 30 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 31 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 32 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 33 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 34 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 35 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 36 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 37 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 38 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 39 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 4 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 40 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 41 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 42 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 43 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 44 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 45 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 46 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 47 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 5 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 6 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 7 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 8 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1
C:\Documents and Settings\Charles  Donaldson\Local Settings\Temp\Temporary Directory 9 for MofikiAutoClickerPremium.zip\Auto Clicker Premium v1.0.0.3.exe   Infected: Backdoor.Win32.Rbot.jnq   1

The selected area was scanned.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 10:23:33 AM
There it is
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 31, 2008, 11:30:35 AM
Clearing Java Cache

Go to Start > Control Panel and double-click the Java IconNote: This deletes ALL the Downloaded Applications and Applets from the CACHE.
.
----------

Download and install CleanUp!.exe (http://stevengould.org/downloads/cleanup/CleanUp452.exe)

Open Cleanup! by double-clicking the icon on your desktop (or from the Start > All Programs menu).
Set the program up as follows:.
Click the CleanUp! button to start the program. Reboot/logoff when prompted.

----------

.
----------

Set a New Restore Point to prevent possible reinfection from an old one
Setting a new restore point AFTER cleaning your system will enable your computer to roll-back to a clean working state if needed.
.
You can find instructions on how to enable and re-enable system restore here:

Windows XP System Restore Guide (http://www.bleepingcomputer.com/forums/tutorial56.html) or Windows Vista System Restore Guide  (http://www.bleepingcomputer.com/tutorials/tutorial143.html)

----------

To prevent unknown applications from being installed on your computer install WinPatrol 2008 (http://www.winpatrol.com/winpatrol.html)
*  Using Winpatrol to protect your computer from malicious software (http://www.winpatrol.com/features.html)

I suggest using SiteAdvisor (http://www.siteadvisor.com/). SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites.

 SpywareBlaster (http://www.javacoolsoftware.com/spywareblaster.html) - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
*  (http://www.bleepingcomputer.com/tutorials/tutorial49.html)Using SpywareBlaster to protect your computer from Spyware and Malware (http://www.bleepingcomputer.com/forums/tutorial49.html)
* If you don't know what ActiveX controls are, see here (http://www.webopedia.com/TERM/A/ActiveX_control.html)

Check out  Keeping Yourself Safe On The Web (http://evilspages.blogspot.com/2008/05/keeping-yourself-safe-on-web.html) for tips and free tools to help keep you safe in the future.

Also see  Slow Computer? It May Not Be Malware (http://evilspages.blogspot.com/2008/05/slow-computer-it-may-not-be-malware.html) for free cleaning/maintenance tools to help keep your computer running smooth.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 11:56:38 AM
^ Hey about the restore point is something weird/bad going to happen to my pc?
 |
 |
 |
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 31, 2008, 12:01:51 PM
Restore Points are sort of like like backup files in Windows format. The oldest ones end up being removed by Windows to make room for the newest ones. All you are doing is making a fresh starting point for them to begin adding up again.
Title: Re: I think I have a virus Ill will Post logs!
Post by: !~*:.Pink Floyd.:*~! on August 31, 2008, 12:57:26 PM
Restore Points are sort of like like backup files in Windows format. The oldest ones end up being removed by Windows to make room for the newest ones. All you are doing is making a fresh starting point for them to begin adding up again.

Works for me.
Also Can anything go horribly wrong during this process?

Sorry im kinda Paranoid : \
Title: Re: I think I have a virus Ill will Post logs!
Post by: evilfantasy on August 31, 2008, 01:00:03 PM
Nothing should go wrong. If you like you can do it this way instead to ensure you don't click any wrong button.

Turn OFF System Restore

.
Restart your computer

Turn ON System Restore.
System Restore will now be active again