Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Need help with malware  (Read 11039 times)

0 Members and 1 Guest are viewing this topic.

evilfantasy

  • Malware Removal Specialist
  • Moderator


  • Genius
  • Calm like a bomb
  • Thanked: 493
  • Experience: Experienced
  • OS: Windows 11
Re: Need help with malware
« Reply #15 on: July 24, 2009, 11:38:47 PM »
Delete any Combo-Fix or ComboFix files you find and also delete the C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt

Then continue on with the next steps.

tryagain

    Topic Starter


    Rookie

    Re: Need help with malware
    « Reply #16 on: July 25, 2009, 01:16:25 PM »
    Ran TFC and the ESET scanner. ESET found three more infections. Posting the ESET log below.

    ESETSmartInstaller@High as CAB hook log:
    OnlineScanner.ocx - registred OK
    # version=6
    # iexplore.exe=7.00.6000.16850 (vista_gdr.090423-0018)
    # OnlineScanner.ocx=1.0.0.5886
    # api_version=3.0.2
    # EOSSerial=0bf9387da20b284496ac34b981e6da16
    # end=finished
    # remove_checked=true
    # archives_checked=false
    # unwanted_checked=true
    # unsafe_checked=false
    # antistealth_checked=false
    # utc_time=2009-07-25 06:35:47
    # local_time=2009-07-25 02:35:47 (-0500, Eastern Daylight Time)
    # country="United States"
    # lang=1033
    # osver=5.1.2600 NT Service Pack 2
    # compatibility_mode=769 21 100 100 158980781250
    # compatibility_mode=5889 61 66 100 729829571093750
    # compatibility_mode=7937 61 100 100 6684428750000
    # scanned=165903
    # found=3
    # cleaned=3
    # scan_time=14799
    C:\Documents and Settings\Owner\My Documents\Nero-8.3.6.0_eng_trial.exe   Win32/Toolbar.AskSBar application (deleted - quarantined)   AB3BAA644A1D8BF50C03C57DE968AE3C   C
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULabwwxiqpeltobirvvjmldunqkeqbrgai.dll.vir   Win32/Olmarik.JI trojan (cleaned by deleting - quarantined)   DB4997444D76434E325050C090B2EFD0   C
    C:\Qoobox\Quarantine\C\WINDOWS\system32\ESQULrbhtkbljbmtclcvtqjoetiwlrtsrtena.dll.vir   Win32/Olmarik.JL trojan (cleaned by deleting - quarantined)   97657EBC7F44A16829661BDB71E6B802   C

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Need help with malware
    « Reply #17 on: July 25, 2009, 01:45:02 PM »
    Those are actually not a real threat.

    How is the computer running now?

    tryagain

      Topic Starter


      Rookie

      Re: Need help with malware
      « Reply #18 on: July 25, 2009, 05:40:07 PM »
      Running better now; not freezing and no pop ups or switched ads. Still sluggish when bringing up or minimizing a screen, switching from internet to email or vice versa.

      My desktop icons grew considerably, before and after I came to Computer Hope, as I tried to get free from malware. Prior to this infection I was running avast, SUPERantispyware, and Windows Defender. When SAS wouldn't run, I downloaded Malwarebytes. When that wouldn't run, I downloaded Spyware Terminator and a-squared. They ran but didn't solve the problem. Then I got help in getting SAS and Malwarebytes to run. So currently I have all of the above (and their get-arounds) plus HiJackThis, Erunt, and NTREGOPT. Should I just go back to avast, SAS, Malwarebytes and Windows Defender and uninstall the rest? Also, is Windows Firewall enough protection or should I look at one of your recommendations?

      I still need to follow the directions for getting my external hard drive up and running again, but I figured I'd wait until the computer gets the all-clear. I have one more question for you. It is possible that I copied some text files to my flash drive at the start of all this (can't remember whether or not it was before the infection). To be safe, I'm thinking I should do a scan and check for infection. Are there any special instructions for this so as not to reinfect this machine or infect another, should the flash have malware?

      Thanks again for all your help and insight!

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Need help with malware
      « Reply #19 on: July 25, 2009, 06:41:00 PM »
      Quote
      Should I just go back to avast, SAS, Malwarebytes and Windows Defender and uninstall the rest?

      Yes!

      Quote
      Also, is Windows Firewall enough protection or should I look at one of your recommendations?

      No.

      Remember only install ONE firewall

      Online Armor
      Sunbelt/Kerio
      Agnitum

      Quote
      Are there any special instructions for this so as not to reinfect this machine or infect another, should the flash have malware?

      Just have your antivirus scan it.

      You can also use this.

      Panda USB and AutoRun Vaccine

      Insert your flash drive before we begin. Hold down the Shift key when inserting the flash drive until Windows detects it to bypass the autorun feature. This will keep the autorun.inf from executing automatically.

      Download Panda USB and AutoRun Vaccine and save it to your desktop. - Alternate download link

      * Extract (unzip) the file to your desktop and a folder named USBVaccine will be created.
      * Open that folder and double-click on USBVaccine.exe to start the program.
      * Click Run
      * Click the button to Vaccinate computer.
      * Insert your USB flash drive.
      * When the name of the drive appears in the dialog box, click the button to Vaccinate USB drive(s).
      * Exit Panda USB and AutoRun Vaccine when done.

      Note: Computer AutoRun Vaccination will prevent any AutoRun file from running, regardless of whether the removable device is infected or not. USB Vaccination disables the autorun file so it cannot be read, modified or replaced by malicious code. The Panda Resarch Blog advises that once USB drives have been vaccinated, they cannot be reversed except with a format. If you do this, be sure to back up your data files first or they will be lost during the formatting process.

      ----------

      Final suggestions.

      Use the Secunia Software Inspector to check for out of date software.
      • Click Start Now
      • Check the box next to Enable thorough system inspection.
      • Click Start
      • Allow the scan to finish and scroll down to see if any updates are needed.
      • Update anything listed.
      .
      ----------

      Go to Microsoft Windows Update and get all critical updates.

      ----------

      I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

      SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
      * Using SpywareBlaster to protect your computer from Spyware and Malware
      * If you don't know what ActiveX controls are, see here

      Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

      Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

      Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

      Semysig



        Greenhorn

        Re: Need help with malware
        « Reply #20 on: August 15, 2009, 04:08:50 PM »
        I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

        SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
        * Using SpywareBlaster to protect your computer from Spyware and Malware
        * If you don't know what ActiveX controls are, see here

        Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ


        Why would one need to run SAS, Spybot, and Malwarebytes?
        Does each do something the other doesn't?

        Also, how does Avast compare to Panda?  Are updates to the virus DB as often?

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Need help with malware
        « Reply #21 on: August 15, 2009, 04:25:11 PM »
        Quote
        Protect yourself against spyware using the Immunize feature in Spybot

        The Immunize feature places restrictions in your HOSTS file to block malicious content on websites.

        Quote
        SAS and Malwarebytes?

        It's best to use at least two on-demand scanners. They will have different definitions and therefore you stand a better chance of catching something with one that the other missed.

        Quote
        Also, how does Avast compare to Panda?  Are updates to the virus DB as often?

        The only real difference is that Panda is not free so it includes live support. The free version of Avast updates multiple times a day sometimes, or whenever they release them.

        They're both good.

        Semysig



          Greenhorn

          Re: Need help with malware
          « Reply #22 on: August 19, 2009, 10:14:23 PM »
          Why would one need to run SAS, Spybot, and Malwarebytes?
          Does each do something the other doesn't?

          Also, how does Avast compare to Panda?  Are updates to the virus DB as often?


          Sweet!  Just the answer I was hoping for :)