Avast WEBforum

Other => Viruses and worms => Topic started by: Yezinki on October 25, 2010, 02:13:46 AM

Title: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 02:13:46 AM
Generally what are the near best possible steps to scan a windows machine for viruses/malware, that isn’t showing any sign/symptoms of being infected just for a clean bill of machine’s health & how should one proceed?

Thanks.
Title: Re: Scanning tools & methods?
Post by: SafeSurf on October 25, 2010, 09:27:38 AM
Are you looking for online scanners or on-demand scanners within your machine?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 12:22:33 PM
Thanks. Both...Avast & MBAM I have......what else should I use for scanning......Trend Micro House Call etc.?
Title: Re: Scanning tools & methods?
Post by: Lisandro on October 25, 2010, 12:24:09 PM
I suggest a full computer on-line scanning:
BitDefender (http://www.bitdefender.com/scan8/ie.html)
ESET NOD32 (http://www.eset.com/onlinescan/)
F-Secure (http://support.f-secure.com/enu/home/ols.shtml)

For detection-only, not cleaning:
Kaspersky (http://www.kaspersky.com/virusscanner)
Trendmicro housecall (http://www.trendmicro.com/hc_intro/default.asp)

Here a very comprehensive information about the on-line scanners (thanks to Polonus):
http://www.techsupportalert.com/freeware-forum/security/1562-online-virus-scanning-services.html
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 12:30:56 PM
Thanks Tech for your suggestions. I appreciate em & would try them after scanning with Avast & MBAM.

Regards!
Title: Re: Scanning tools & methods?
Post by: Lisandro on October 25, 2010, 12:35:03 PM
You're welcome.
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 02:23:56 PM
Tech F-Secure on line scanning detected a tracking cookie.......win32admt......how does one block such while using G Chrome browser?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 02:28:15 PM
Bit Defender Quick scan results no infection found. I am doing all 3 scan simultaneously one after the other. No clues how these cookie get into G Chrome never had these issues with IE?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 03:34:46 PM
ESET NOD32 scan is clean too. Is there an option to block such tracking cookies in G Chrome? Would this help........  https://chrome.google.com/extensions/detail/gighmmpiobklfepjocnamgkkbiglidom?hl=en-US?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 03:47:16 PM
This add block is a good Chrome extension.

Tech how do I uninstall FSecure & ESET NOD32 Files & folders, some of which are seen only as invisible C>..?
Title: Re: Scanning tools & methods?
Post by: DavidR on October 25, 2010, 03:48:47 PM
Tracking cookies area a waste of processing effort to even check. Not to mention it is one which can be largely removed by having your browser block 3rd party cookies.

Don't worry about reported tracking cookies they are a minor issue and not one of security, allow it to deal with them though. - See http://en.wikipedia.org/wiki/HTTP_cookie (http://en.wikipedia.org/wiki/HTTP_cookie).
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:10:32 PM
Thanks DavidR. How do I delete them?

Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 04:12:45 PM
This is my favorite: http://www.surfright.nl/en/hitmanpro/ (http://www.surfright.nl/en/hitmanpro/)
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:20:42 PM
Here Omid.
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:26:39 PM
Hi Omid 2 questions: How do I prevent these cookies despite installing adblock ext for chrome & method to delete invisible files installed by F-Secure & ESET NODE32?

Regards!
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 04:30:17 PM
Hi Omid 2 questions: How do I prevent these cookies despite installing adblock ext for chrome & method to delete invisible files installed by F-Secure & ESET NODE32?

Regards!

Try enable this option and see if it works:
Title: Re: Scanning tools & methods?
Post by: DavidR on October 25, 2010, 04:41:29 PM
Thanks DavidR. How do I delete them?

The images you displayed are nothing to do with tracking cookies (so I'm confused) they are files or folders and if detected as tracking cookies the scan is not accurate.

Just clear all cookies in your browsers.

I use firefox and the cookie monster add-on, I have 3rd party cookies in firefox disabled and cookie monster by default only allows session cookies unless you give permission for a permanent site cookie. That way when you shutdown your browser or system all the session  cookies are removed only the ones you gave permission to remain.
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:42:32 PM
It helped BIG TIME Omid......now the Hitman scan is clean.

How do I delete the files?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:45:42 PM
Thanks DavidR. How do I delete them?

The images you displayed are nothing to do with tracking cookies (so I'm confused) they are files or folders and if detected as tracking cookies the scan is not accurate.


The images display the invisibles folders, files installed by F-Secure online scanning.
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 04:50:38 PM
Thanks DavidR. How do I delete them?
These are system files, I don't think you should delete them  ???, I'm sorry to jump between you and david  :-[

It helped BIG TIME Omid......now the Hitman scan is clean.
I'm glad it helped you ;)
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 04:52:49 PM
I agree they are system file but appeared after a F-Secure on line scanning........am I correct?
Title: Re: Scanning tools & methods?
Post by: DavidR on October 25, 2010, 04:55:43 PM
As was mentioned, they aren't f-secure folders, but for the most part system files/folders.

If f-secure creates folders, etc. then I would assume there would be some sort of add remove programs entry for f-secure ?

But clearing your temp folders, reboot and see what is there.
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 04:58:09 PM
I agree they are system file but appeared after a F-Secure on line scanning........am I correct?
They have nothing to do with F-Secure.
Desktop.ini will save customization of each folder, like Folder picture etc.
Boot.ini, config.sys etc are windows configuration needed to boot windows
Recyler is where windows save file you move to recycle bin
System Volume information is clear from it's name...

Maybe F-Secure had impact on Windows Folder options settings and disabled "Hide Protected System Files"
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 05:06:49 PM
Thanks DavidR & Omid....I think the "show all files" got checked.......the online scan performed by F-Secure, ESET NODE32 & BitDefender increased the size of system drive by approx 400MB, where would these be... in the Temp folders...deleting & rebooting might give an idea......do I need to perform a Hijack scan or a House Call.......G Chrome has good extensions....ad block really helped along with block all 3rd party cookies....any other suggestions for Chrome regarding security......Omid your blog, website & forums look nice.......gives me ideas how to start working on mine. :)

Best Regards!
Title: Re: Scanning tools & methods?
Post by: DavidR on October 25, 2010, 06:27:32 PM
Personally I think you should leave it that way so you see what is on your system and not have the default to hide system files and folders, as some malware takes advantage of that hidden option.
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 07:00:20 PM
Agreed 100%....But is there a possibility that the F-Secure> Online Full Scan or Hitman Pro, made them appear, coz I had the option of show all files checked even before the scan, but these appeared later? :-\

Thanks again.
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 07:23:59 PM
Agreed 100%....But is there a possibility that the F-Secure> Online Full Scan or Hitman Pro, made them appear, coz I had the option of show all files checked even before the scan, but these appeared later? :-\

Thanks again.

They Fixed it  ;D
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 25, 2010, 07:25:18 PM
I had a gut feelin.....you are a genius Omid. Thanks again!
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 25, 2010, 07:34:40 PM
Thanks Yezinki, Es Macht Nichts!!
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 26, 2010, 07:19:45 PM
I am still getting these tracking cookies..any clues why?
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 26, 2010, 07:22:40 PM
I am still getting these tracking cookies..any clues why?

I don't know a very effective cookie management/blocker for Chrome like there are for IE/FF

You may try this, but this large list of blocked URLs will slightly slow-down lunching programs: http://www.javacoolsoftware.com/spywareblaster.html
Title: Re: Scanning tools & methods?
Post by: Pondus on October 26, 2010, 07:28:13 PM
HTTP cookie 
http://en.wikipedia.org/wiki/HTTP_cookie

Are cookies really spyware and are they dangerous?
http://www.superantispyware.com/supportfaqdisplay.html?faq=26
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 26, 2010, 07:35:37 PM
Still when I read what they have stored (http://forum.qip.ru/images/smilies/rtfm.gif) I don't like them! (http://forum.qip.ru/images/smilies/spiteful.gif)
Title: Re: Scanning tools & methods?
Post by: DavidR on October 26, 2010, 07:56:51 PM
I am still getting these tracking cookies..any clues why?

Sorry but this hitman pro making a big deal out of nothing. These look like nothing other than bog standard cookies, from the sites that you visited. If they aren't sites that you visited then you haven't blocked 3rd party cookies as we suggested or you haven't cleared the cookies after having changed the 3rd party cookies option.

You really are wasting your time being concerned with this low level cr*p.
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 26, 2010, 08:00:24 PM
Sorry but this hitman pro making a big deal out of nothing. These look like nothing other than bog standard cookies, from the sites that you visited. If they aren't sites that you visited then you haven't blocked 3rd party cookies as we suggested or you haven't cleared the cookies after having changed the 3rd party cookies option.

You really are wasting your time being concerned with this low level cr*p.
These are cookies from Ads showing in other sites, is it 3rd or not? ??? (also this not Chrome location, FF and IE seems has not been set for that)
Title: Re: Scanning tools & methods?
Post by: DavidR on October 26, 2010, 08:06:51 PM
Yes, they are ad related sites yeildmanager and atdmt and that is why I got on about 3rd party cookies option as it would be rather unusual to actually visit these sites.

If Yezinki didn't visit the sites, then as I said they are either old cookies or Yezinki hasn't applied the 3rd party cookie suggestion to all browsers as we mentioned. Only Yezinki can answers any of the above.
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 26, 2010, 08:57:29 PM
3rd party cookies blocked, no browsing on this machine except Yahoo, Windows Live messengers, G Chrome browser, Avast forums and Ad Thwart installed?
Title: Re: Scanning tools & methods?
Post by: DavidR on October 26, 2010, 09:05:09 PM
Yes, but as Omid said, that is only chrome, you have to do the same in the other browsers you use.

Also were these old cookies and were they related to chrome that were found, given the location Omid doesn't think they a\re for chrome ?
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 26, 2010, 09:05:32 PM
I am still getting these tracking cookies..any clues why?

I don't know a very effective cookie management/blocker for Chrome like there are for IE/FF

You may try this, but this large list of blocked URLs will slightly slow-down lunching programs: http://www.javacoolsoftware.com/spywareblaster.html

Spyware blaster has no option for Chrome.

Regards!
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 26, 2010, 09:10:42 PM
Despite being deleted by Hit man on rescan they reappear in C>Documents & Settings> Vaio> Cookies> vaio@yeildmanger(1)text.?

Regards!
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 26, 2010, 09:18:20 PM
That location belong to Microsoft Windows itself, maybe IE or something IE based loaded them, like ads in Windows Live Messenger or Yahoo Messenger. Since that is based on IE, I think SpywareBlaster will take care of it. HostsMan can help by blocking Ads domain too (so will affect Chrome too ;) )
Title: Re: Scanning tools & methods?
Post by: Yezinki on October 26, 2010, 09:21:35 PM
Omid I don't think Spyware blaster can incocculate Chrome. :-\

Regards!
Title: Re: Scanning tools & methods?
Post by: Omid Farhang on October 26, 2010, 09:29:26 PM
Omid I don't think Spyware blaster can incocculate Chrome. :-\

Regards!

I did not said it affect chrome... I said HostsMan will affect while traffic (and Chrome too).
I said SpywareBlaster will affect IE and IE based stuff like Ads inside Yahoo Messenger and Live Messenger.