Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: please help ? virus or what?  (Read 12936 times)

0 Members and 2 Guests are viewing this topic.

computeridiot

    Topic Starter


    Rookie

    Re: please help ? virus or what?
    « Reply #15 on: October 01, 2008, 11:53:01 AM »
    It says free user or premium user what do i select as it didn't give me a choice on administrator rights.

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: please help ? virus or what?
    « Reply #16 on: October 01, 2008, 11:54:08 AM »
    Free user.

    Just follow the instructions and boot into safe mode then wait for the tool to run.

    computeridiot

      Topic Starter


      Rookie

      Re: please help ? virus or what?
      « Reply #17 on: October 01, 2008, 12:18:05 PM »
      Problem 1. I got safe mode, put the arrow key up to select it, nothing happened so I pressed the return key, got a load of techie jargon that just sat there. So I pressed enter/return again and it gave me options of safe mode / safemode with networking or safe mode with prompt command, keyed up to safe mode again, got the techie jargon and we went round and round in circles, in the end I had to select normal start up to get back in again.

      Problem 2. I then got a firewall warning that OCR aware (32-bit) was attempting to monitor or intercept system events, what is it and do I allow or block.


      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: please help ? virus or what?
      « Reply #18 on: October 01, 2008, 12:25:29 PM »
      Download Malwarebytes' Anti-Malware (MBAM) http://rapidshare.com/files/150037339/mbam-setup.exe.html

      • Double-click mbam-setup.exe and follow the prompts to install the program.
      • At the end, be sure a checkmark is placed next to the following:
        • Update Malwarebytes' Anti-Malware
        • Launch Malwarebytes' Anti-Malware
        • Then click Finish.
        • If an update is found, it will download and install the latest version.
        • Once the program has loaded, select Perform quick scan, then click Scan.
        • When the scan is complete, click OK, then Show Results to view the results.
        • Be sure that everything is checked, and click Remove Selected.
        • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
        • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
        • Copy and Paste the entire report in your next reply.
        Extra Note: If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.

        computeridiot

          Topic Starter


          Rookie

          Re: please help ? virus or what?
          « Reply #19 on: October 01, 2008, 12:29:01 PM »
          Thought that was the one I just tried to do??

          What do I do about the firewall warning do I accept or block?

          computeridiot

            Topic Starter


            Rookie

            Re: please help ? virus or what?
            « Reply #20 on: October 01, 2008, 12:41:41 PM »
            Will do the scan, but need to know about the firewall warning, was it to do with the thing I just downloaded the first one and if so do I select block?

            evilfantasy

            • Malware Removal Specialist
            • Moderator


            • Genius
            • Calm like a bomb
            • Thanked: 493
            • Experience: Experienced
            • OS: Windows 11
            Re: please help ? virus or what?
            « Reply #21 on: October 01, 2008, 12:52:58 PM »
            You shouldn't get any warnings from Malwarebytes' Anti-Malware, if you do then allow it to run.

            Blocking things while downloading them sort of defeats the whole process....

            computeridiot

              Topic Starter


              Rookie

              Re: please help ? virus or what?
              « Reply #22 on: October 01, 2008, 12:58:09 PM »
              No i didn't block anything from malwarebytes but I did get a lot of requests from my firewall for access which I allowed.

              The other pop up came after I tried safe mode and don't know if it was connected with the previous thing you asked me to download or not so I just blocked it anyway.

              Heres the scan and funnily enough after I ran it avast updated automatically which it hasn't been able to today.

               Malwarebytes' Anti-Malware 1.28
              Database version: 1226
              Windows 5.1.2600 Service Pack 3

              01/10/2008 19:50:08
              mbam-log-2008-10-01 (19-50-08).txt

              Scan type: Quick Scan
              Objects scanned: 41057
              Time elapsed: 2 minute(s), 51 second(s)

              Memory Processes Infected: 0
              Memory Modules Infected: 0
              Registry Keys Infected: 2
              Registry Values Infected: 0
              Registry Data Items Infected: 3
              Folders Infected: 0
              Files Infected: 2

              Memory Processes Infected:
              (No malicious items detected)

              Memory Modules Infected:
              (No malicious items detected)

              Registry Keys Infected:
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\tdssdata (Trojan.Agent) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\tdss (Trojan.Agent) -> Quarantined and deleted successfully.

              Registry Values Infected:
              (No malicious items detected)

              Registry Data Items Infected:
              HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SecurityProviders\SecurityProviders (Broken.SecurityProviders) -> Bad: (msapsspc.dllschannel.dlldigest.dllmsnss pc.dll) Good: (msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll) -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: c:\windows\system32\ -> Quarantined and deleted successfully.
              HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Trojan.Agent) -> Data: system32\ -> Quarantined and deleted successfully.

              Folders Infected:
              (No malicious items detected)

              Files Infected:
              C:\WINDOWS\system32\ (Trojan.Agent) -> Quarantined and deleted successfully.
              C:\WINDOWS\system32\drivers\ (Trojan.Agent) -> Quarantined and deleted successfully.

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: please help ? virus or what?
              « Reply #23 on: October 01, 2008, 01:01:47 PM »
              You will have to turn off all of your protection to run ComboFix. Directions will be included if you need them.

              Download HostsXpert
              • Unzip HostXpert to your Desktop
              • Open up the HostXpert program.
              • Make sure that the "Make Hosts Writable?" button in the upper right corner is enabled.
              • Click Create Back Up
              • Then click on Restore Microsoft's Host Files
              • Close the HostXpert program
              .
              Note: if you use SpywareBlaster, Spybot and/or IE-SPYAD, it will be necessary to re-install the protection they afford. For SpywareBlaster, run the program and select Enable all protection. For Spybot run the program and select Immunize. For IE-SPYAD, run the batch file and reinstall the protection.

              ----------

              Download ComboFix by sUBs from one of the below links. Be sure top save it to the Desktop.

              Link #1
              Link #2

              **Note:  It is important that it is saved directly to your Desktop

              Close any open Web browsers. (Firefox, Internet Explorer, etc) before starting ComboFix.

              Temporarily disable your antivirus, and any antispyware real time protection before performing a scan. Click this link to see a list of security programs that should be disabled and how to disable them.
               
              Double click combofix.exe & follow the prompts.
              When finished ComboFix will produce a log for you.
              Post the ComboFix log and a new HijackThis log in your next reply.

              Important: Do not mouseclick ComboFix's window while it is running. That may cause it to stall.

              Remember to re-enable your antivirus and antispyware protection when ComboFix is complete.

              computeridiot

                Topic Starter


                Rookie

                Re: please help ? virus or what?
                « Reply #24 on: October 01, 2008, 01:03:24 PM »
                Do i need to do that as the last scan seems to have sorted the problem out and can get on the sites ok now but will do so if you still advise it.

                evilfantasy

                • Malware Removal Specialist
                • Moderator


                • Genius
                • Calm like a bomb
                • Thanked: 493
                • Experience: Experienced
                • OS: Windows 11
                Re: please help ? virus or what?
                « Reply #25 on: October 01, 2008, 01:07:14 PM »
                Please keep following all instructions until I give the all clear. Lack of symptoms is not a reliable indication that the malware is gone.

                computeridiot

                  Topic Starter


                  Rookie

                  Re: please help ? virus or what?
                  « Reply #26 on: October 01, 2008, 01:09:34 PM »
                  OK will do. We did do all this a few weeks ago and I have a firewall / antivirus / spyware thingies so how did I get those trojans?????????????


                  Off to do as requested.

                  computeridiot

                    Topic Starter


                    Rookie

                    Re: please help ? virus or what?
                    « Reply #27 on: October 01, 2008, 01:17:52 PM »
                    Problems again, i clicked on hostsxpert and it came up with a site called funkytoad.com and said what i want'ed didn't exist.

                    Any ideas?

                    computeridiot

                      Topic Starter


                      Rookie

                      Re: please help ? virus or what?
                      « Reply #28 on: October 01, 2008, 01:23:21 PM »
                      Yep still have problems, clicked on the BBC weather site and got something really weird, its very random.

                      computeridiot

                        Topic Starter


                        Rookie

                        Re: please help ? virus or what?
                        « Reply #29 on: October 01, 2008, 01:25:13 PM »
                        OK think i have found hostxpert on another site so will download it and let you know.