Author Topic: A double check please  (Read 1432 times)

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
A double check please
« on: March 25, 2012, 06:32:28 AM »
Hi,Did a couple of scans with SAS yesterday and found some files called  "trace.known threat sources" SAS removed them but I'd like you guys to please just double check that their definitely gone.
OS is windows 7 Home Premium
Thanks
Jamie
Malwarebytes' Anti-Malware 1.51.2.1300
www.malwarebytes.org

Database version: 7827

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

29/09/2011 10:22:13 PM
mbam-log-2011-09-29 (22-22-13).txt

Scan type: Quick scan
Objects scanned: 178669
Time elapsed: 1 minute(s), 35 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
« Last Edit: March 25, 2012, 06:34:07 AM by jamiebosco »

Offline mikaelrask

  • avast! Evangelist
  • Advanced Poster
  • ***
  • Posts: 1143
  • Gender: Male
    • Personal Message (Offline)
Re: A double check please
« Reply #1 on: March 25, 2012, 08:02:14 AM »
hey and welcome to the forum jamiebosco. someone of our malware expert here will check those logs and give you further instruction if needed.

are you having any trouble on your computer after sas had removed those threts?

what avast version you using free/pro/suite?
new computer
windows 8 Intel core I-3 64 bit
6 gb ram 500 gb hardrive. avast 8 MBAM

Offline Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17103
  • Gender: Male
    • Personal Message (Offline)
Re: A double check please
« Reply #2 on: March 25, 2012, 08:05:22 AM »
also attache SAS log so that essexboy can see what was removed   ;)
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #3 on: March 25, 2012, 09:02:18 AM »
hey and welcome to the forum jamiebosco. someone of our malware expert here will check those logs and give you further instruction if needed.

are you having any trouble on your computer after sas had removed those threts?

what avast version you using free/pro/suite?
No problems at the moment,computer is a little slow at times but nothing major.

I'm using avast free ( 7.0.1426).

I scanned with malwarebytes right before SAS and MBAM didn't find anything.The first SAS scan found 1 file (trace.known threat sources)and removed it and asked me to restart.After the restart I scanned again and found 2 files ("trace.known threat sources" again)and restarted again.Scanned again after restart and came up clean.Have scanned several times today with no more files
Thanks
jamie

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #4 on: March 25, 2012, 09:09:43 AM »
also attache SAS log so that essexboy can see what was removed   ;)
sorry I've done quite a few SAS scans since the 2 that found the "trace.known threat sources" files and now the only logs available to see are clean ones
The files are still in quarentine if that helps?
jamie

Offline Pondus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 17103
  • Gender: Male
    • Personal Message (Offline)
Re: A double check please
« Reply #5 on: March 25, 2012, 09:43:47 AM »
And one more thing......the malwarebytes log You posted is from 2011-09-29
Chief Wiggum: Uh, no, you got the wrong number. This is 9-1…2.

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #6 on: March 25, 2012, 09:56:37 AM »
And one more thing......the malwarebytes log You posted is from 2011-09-29

Whoops!   it was the one at the top so I thought it was the newest
I'll do another one now
thanks

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #7 on: March 25, 2012, 09:57:56 AM »
And one more thing......the malwarebytes log You posted is from 2011-09-29

Malwarebytes Anti-Malware 1.60.1.1000
www.malwarebytes.org

Database version: v2012.03.25.01

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 8.0.7601.17514
Jamie :: JAMIE-PC [administrator]

25/03/2012 3:43:35 PM
mbam-log-2012-03-25 (15-43-35).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 207590
Time elapsed: 1 minute(s), 49 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22322
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: A double check please
« Reply #8 on: March 25, 2012, 12:08:36 PM »
Nothing apparent in the logs - is it just a general slowness that you are getting or only on boot ?




Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #9 on: March 25, 2012, 12:35:49 PM »
Nothing apparent in the logs - is it just a general slowness that you are getting or only on boot ?
Hi,
Just general slowness really,nothing too bad.Internet explorer has shut down on me a few times lately as well,that's what prompted me to do the MBAM and SAS scans in the first place.Maybe Java related?
Thanks for the help
jamie
« Last Edit: March 26, 2012, 07:53:25 AM by jamiebosco »

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22322
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: A double check please
« Reply #10 on: March 25, 2012, 12:48:37 PM »
No problem - empty the temp files and run a defrag, that sometimes helps

 



Offline polonus

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 16939
  • Gender: Male
  • malware fighter
    • Personal Message (Offline)
Re: A double check please
« Reply #11 on: March 25, 2012, 12:50:29 PM »
Hi jamiebosco,

It migt be a good idea to visit here: secunia.com/vulnerability_scanning/online/ 
There you could do a check of the software on your comp is fully updated and patched,

polonus
Cybersecurity is more of an attitude than anything else. Avast Evangelists.

Use NoScript, a limited user account and a virtual machine and be safe(r)!

Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #12 on: March 25, 2012, 09:33:13 PM »
I did a scan with TDSS and it found a file but won't let me cure it,I can skip,copy to quarentine,and delete
Here's the log

Offline essexboy

  • avast! Überevangelist
  • Maybe Bot
  • *****
  • Posts: 22322
  • Gender: Male
  • Dragons by Sasha
    • Malware fixes
    • Personal Message (Offline)
Re: A double check please
« Reply #13 on: March 25, 2012, 09:36:25 PM »
Quote
\Device\Harddisk1\DR1 ( TDSS File System )
This can be deleted, it is a copy of the malware files (inert) 



Offline jamiebosco

  • Newbie
  • *
  • Posts: 15
    • Personal Message (Offline)
Re: A double check please
« Reply #14 on: March 26, 2012, 07:54:50 AM »
Thanks again for the help,seems all clear at the moment

jamie