Author Topic: Need help with infection  (Read 17696 times)

0 Members and 1 Guest are viewing this topic.

Nikilet

  • Guest
Re: Need help with infection
« Reply #15 on: July 10, 2012, 10:19:07 PM »
Will do! And thanks for your excellent help, as always.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #16 on: July 10, 2012, 10:22:32 PM »
Shucks, not a problem  ;D

Nikilet

  • Guest
Re: Need help with infection
« Reply #17 on: July 11, 2012, 12:10:52 AM »
I ran another boot scan and this time it says it found a rootkit and again suggests I run another boot scan. Wish I would have taken a screenshot of the rootkit warning window. Darn! I'll run another boot scan and post back.

(Later) -- Ok, I ran ANOTHER boot scan. This time no infections except the corrupted file below. But can you tell me why I would end up with Win32:Malware-gen and a rootkit when I have Avast Internet Security, Malwarebytes Pro, Win Patrol -- I keep things updated, probably run more scans than anyone you know? I'm concerned. I made a payment to my credit card yesterday. Do I have to worry about that?

Do I need your instructions to get rid of OLT, ComboFix and aswMBR from my desktop? I know one time you gave me instructions for cleaning things up.

Another thing that has been found each time is C\Users\me\AppData\Roaming\SUPERAntiSpyware.com\SUPER
AntiSpyware\Quarantine\quarantine.db l>date errir 42125 (zip file is corrupted)
What should I do with this -- if anything?
« Last Edit: July 11, 2012, 01:56:48 AM by Nikilet »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #18 on: July 11, 2012, 03:31:43 PM »
Malware writers are adjusting the programmes on a daily basis so that they can outwit the AV companies.  And they succeed due to the fact that they know how the Antivirus programme operates

A corrupt archive can either be deleted or left, it is of no consequence

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Quote
    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
Remove ComboFix

  • Hold down the Windows key + R on your keyboard. This will display the Run dialogue box
  • In the Run box, type in ComboFix /Uninstall (Notice the space between the "x" and "/") then click OK



  • Follow the prompts on the screen
  • A message should appear confirming that ComboFix was uninstalled
Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Go to control panel
  • Select folder options (Appearance > Folder options in category view)
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
SPRING CLEAN

To manually create a new Restore Point
 
  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create
Now we can purge the infected ones
  • GoStart > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete
Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.  Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit
To learn more about how to protect yourself while on the internet read our little guide  How did I get infected in the first place ?

Keep safe  :wave:

Nikilet

  • Guest
Re: Need help with infection
« Reply #19 on: July 12, 2012, 02:17:18 AM »
Thank you!
     Thank you!
          Thank you!

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #20 on: July 12, 2012, 07:31:30 PM »
My pleasure  ;D

Nikilet

  • Guest
Re: Need help with infection
« Reply #21 on: July 12, 2012, 08:21:06 PM »
Something just dawned on me. You commented below: Now the best part of the day ----- Your log now appears clean  :thumbsup:

Thing is, after I did that last boot scan to see if the rootkit had been removed, I didn't send you any new logs so that clean log would have been from before the rootkit. I'm assuming this is because the tools you gave me to run would not have detected a rootkit ... Is this correct?

Is it normal for a rootkit to have gotten past my security measures? I don't go to anything like porn sites or off-the-wall sites. My Internet usage is very tame.

Also, the fact that I used my credit card service for both charges and payments while I apparently had this Win32:Malware-gen and a rootkit on my system ... Should I be concerned about this?


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #22 on: July 12, 2012, 08:31:41 PM »
It is always worth after an infection to ask your bank to monitor your account for a while

What was the location of the detected file .. Was it in Qoobox or OTL moved files ?

Nikilet

  • Guest
Re: Need help with infection
« Reply #23 on: July 12, 2012, 08:35:58 PM »
I have no idea. The avast window popped up telling me a rootkit had been detected and should be removed right away. I clicked on the box to remove it and am afraid I didn't read or look close enough -- think I got panicked! Then after I clicked to delete it I was advised to run another boot scan, which I did, and it showed clean. Is there any way to find out what this item I deleted was?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #24 on: July 12, 2012, 08:47:45 PM »
The log should be here  C:/Program Data/Avast Software/Avast/Report/aswBoot.txt

Nikilet

  • Guest
Re: Need help with infection
« Reply #25 on: July 12, 2012, 09:38:42 PM »
I found the log; did you want it?

Funny thing is, there is no mention of a rootkit detection. I promise you that it was an avast window that appeared and said a rootkit had been detected and this item should be removed right away; then gave a box to click for deleting it; then asked for another boot scan to make sure the infection was cleared. The two scans I did on 7-10 both show 0 infections.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Need help with infection
« Reply #26 on: July 12, 2012, 11:00:12 PM »
No I trust you, I wonder whether it detected the quarantined files that we had tucked away...  How is the computer behaving ?  Still good

 

Nikilet

  • Guest
Re: Need help with infection
« Reply #27 on: July 13, 2012, 02:33:00 AM »
Everything appears to be good. The quarantined files dealt with Win32:Malware-gen, and this would not be a rootkit would it?

My computer seems to be acting fine. I'm just very curious as to why avast would have shown a rootkit, but yet it wasn't in the report. Even if it was removed it seems it still should have shown up in the report.

I'll maybe start doing a boot scan occasionally. Only thing is, it takes so long to complete, and if you aren't sitting right here it closes out and you don't know what was there -- except I guess now I could go into that location you gave me and check: C:/Program Data/Avast Software/Avast/Report/aswBoot.txt.

SafeSurf

  • Guest
Re: Need help with infection
« Reply #28 on: July 13, 2012, 11:35:32 AM »
Nikilet,

If you are concerned with the financial transactions, as Essexboy mentioned, have your financial companies monitor for a while (ask to speak to the Fraud Dept.), put a Fraud Alert on your credit reporting agencies (good for 90 days, then keep renewing - free), ask your bank and/or credit card company to change your account number if you are really concerned, do a free Annual Credit check (you can do one quarterly with each of the 3 companies in the US), keep checking online your transactions, and change your passwords on the accounts you used (make them stronger as well).

Nikilet

  • Guest
Re: Need help with infection
« Reply #29 on: July 24, 2012, 03:53:01 AM »
I'm reopening this because I think there may be something funny going on with avast. If you will review the above, avast advised of a rootkit found but nothing showed up in the boot scan. Now it happened again. I hadn't had my computer on for 5 days as I was gone. I came home and turned it on. When I booted everything came up but it appeared to be frozen so I had to do a forced shutdown and restart. It did boot, but shortly after boot avast again popped up with a rootkit warning. I didn't delete or take any action but I did take a picture of the screen this time. This rootkit seems to have something to do with Malwarebytes. That doesn't seem right. Is avast giving some kind of false positive?

I really hate to say this but just recently avast seems to be acting up a bit on my system. It seems to really take a long time to boot up whereas it never used to. I have plenty of RAM, and I don't have that much extra running at startup. For instance, I start Malwarebytes immediately after everything has loaded and do not have it set to auto start at boot.