Author Topic: Malware/Trojans  (Read 26440 times)

0 Members and 1 Guest are viewing this topic.

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #30 on: July 29, 2012, 05:55:14 AM »
Hi

Give it one more try then try in safe mode. Again I do not believe it is of concern but it will make us both feel better if it runs.

To boot to safe mode:
  • Restart your computer
  • After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
  • Instead of Windows loading as normal, a menu with options should appear;
  • Select the first option, to run Windows in Safe Mode, then press "Enter".
  • Choose your usual account.

JackSession

  • Guest
Re: Malware/Trojans
« Reply #31 on: July 29, 2012, 09:12:25 PM »
good morning!!

i ran aswMBR again and it went a little different this time...it stopped at:

C:\Documents and Settings\Administrator\Local Settings\Application Data... (I couldnt see the rest)

the computer immediately restarted..when it was done booting I got a message saying "Microsoft Windows has recovered from a serious error...." these were the errors that occured:

C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WERb1d8.dir00\Mini072912-01.dmp
C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\WERb1d8.dir00\sysdata.xml

Going to try it in safemode now...

Thanks

Jack :)

JackSession

  • Guest
Re: Malware/Trojans
« Reply #32 on: July 29, 2012, 09:52:12 PM »
aswMBR ran complete in Safe Mode...here's the log...

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #33 on: July 29, 2012, 11:20:08 PM »
Hi JackSession,

It looks ok. We'll check one more thing. There should be a file on your desktop called mbr.dat. Rename it to mbr.txt and attach it to your next reply.

JackSession

  • Guest
Re: Malware/Trojans
« Reply #34 on: July 29, 2012, 11:31:44 PM »
hi oldman..not sure if i didnt that right...no program to open dat files

JackSession

  • Guest
Re: Malware/Trojans
« Reply #35 on: July 29, 2012, 11:39:49 PM »
hi oldman..i saw this on another posting:

"**WARNING**Unfortunately one or more of the infections I have identified are Backdoor Trojans, IRCBots or other Malware capable of stealing very important information. You need to stop using all Internet Banking sites, change passwords to all sites with sensitive information from a clean computer and phone your bank to inform them that you may be a victim of identify theft. More often than not, we advise users that a full reinstallation of their Operating System is the only way to ensure that their computer will ever be 100% clean again."

was my deal this bad? should i assume my info has been compromised?

thanks

jack :)

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #36 on: July 30, 2012, 02:22:34 AM »
Hi JackSession,

I thought I had suggested that you change all your passwords to any forums or financial institutes that you may deal with but looking back throught the topic I don't see it. I think changing you passwords should be enough.

The mbr checks out clean.

Any issues?

Poat back after you are finished and I'll give you some instructions to safely transfer some tools to your other computer.

From your desktop, please delete, if present
  • any notepads/logs that we created
  • GMER (df807stx.exe)
  • aswMBR.exe
  • mbr.txt
  • aswMBR.txt 
  • TDSSKiller
  • RogueKiller

Next

Click the Start button, click Run.  Copy and paste the following line into the run box and click OK

Combofix /uninstall

Open OTL then click the Clean Up button. You may get prompted by your firewall that OTL wants to contact the internet -  allow this.  A cleanup.txt will be downloaded, a message dialog will ask you if you want to proceed with the cleanup process, click Yes. This will do some clean up tasks and delete some of the tools you have downloaded plus itself.

I suggest you keep MBAM. Keep it updated and use it regularly.

Some Recommendations and prevention tips

Basic security consists of 1 antivirus program, 1 resident antispyware program, 1 on demand antispyware program and a firewall.

I suggest either for a resident antispyware program.

Windows Defender
 OR
Winpatrol

* If you are behind a router Windows firewall should be fine. Otherwise a 3rd party firewall with outbound monitoring is recommended.

Click FIREWALL for links and tutorials to good, free and paid for firewalls. (Note: Zone Alarm is becoming bloatware, IMO)

You should also use Spyware Blaster to help immunize your computer.

 - SpywareBlaster will add a large list of programs and sites into your Internet Explorer
settings that will protect you from running and downloading known malicious programs.
 
OR

A guide to understanding and using the hosts file.

Learn how your Hosts file can protect you and how you can protect it.
Besides the Hosts file information, there are links to a very good updated hosts file, a host file manager. and some programs that can protect your hosts file.
HOSTS

Please read the info on disabling the DNS Client before installing a custom hosts file.

-Secure your Internet Explorer

From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
  • Change the Download signed ActiveX controls to Prompt
  • Change the Download unsigned ActiveX controls to Disable
  • Change the Initialize and script ActiveX controls not marked as safe to Disable
  • Change the Installation of desktop items to Prompt
  • Change the Launching programs and files in an IFRAME to Prompt
  • Change the Navigate sub-frames across different domains to Prompt
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Next press the Apply button and then the OK to exit the Internet Properties page.

- Keeping your Windows up-to-date is crucial to your computer's security. Please go to the Windows Update Site (using Internet Explorer) and download and install all critical updates on a regular basis

- Make sure you have reset Automatic Updates to your chosen optionClick your start button > Control Panel > System

- Keep your antivirus program updated, as well as any other security programs you have.

-More tips and programs can be found HERE

 Please post back if you have any problems.


JackSession

  • Guest
Re: Malware/Trojans
« Reply #37 on: July 30, 2012, 05:01:41 AM »
ill will do all of this stuff tomorrow and see...i really appreciate your help :)

the only issue is my gf has been complaining about youtube and other video content slowing down since we did this stuff..i turned mbam and avast! completely off and it still seems to be doing it...any ideas?

other than that everything is running smoothly

Thanks!

Jack :)

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #38 on: July 30, 2012, 06:35:59 AM »
Hi JackSession,

Other than when we ran combofix and the OTL fix the rest of the scans we did were just scans that will not remove anything. I looked at both the combofix log and the OTL fix and there doesn't seem to be anything related to what you are describing in either of those. We did empty a bunch of temporary caches, flash being one of them.

Try updating Flashlayer perhaps?

JackSession

  • Guest
Re: Malware/Trojans
« Reply #39 on: July 30, 2012, 11:24:49 PM »
Hi Oldman,

Cleaned everything up as instructed. Installed Windows Defender and SpywareBlaster. Have Malwarebytes and Avast! running. Also updated the Flash Player and Firefox. Everything is running great!!

I need to get a USB stick before I can do this stuff on the other computer. I will either start a new topic or continue here when I am ready...whichever you prefer.

I really appreciate your help here-  Very informative and professional.

Thank You!!

Jack :)

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #40 on: July 31, 2012, 12:42:55 AM »
Hi JackSession,

Great! You're more than welcome.

Let's continue in this topic so I don't lose track of you. I'll keep watching this topic.

A writable CD should work in a pinch if you can't get a flashdrive. Flashdrives are pretty cheap these days though.

See you soon.  :)

JackSession

  • Guest
Re: Malware/Trojans
« Reply #41 on: July 31, 2012, 01:06:25 AM »
as far as the issue with youtube skipping...its still happening

i shut everything else down to see if that was the problem..it plays ok as long as i do nothing else with the computer..even scrolling up and down will cause it

so i reset windows virtual memory to 1500/1500 (i have 1.49g RAM)...cleaned up the hard drive so its now over 25% free..cleared all the temp internet files..updated flash and shockwave...still doing it...

the only thing i can guess at this point is that the cookies etc were allowing it to run quicker..now that they are gone they need to be replaced to play as they did before?

JackSession

  • Guest
Re: Malware/Trojans
« Reply #42 on: July 31, 2012, 02:03:22 AM »
its not doing the skipping in IE...only FF..

Offline oldman

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 4142
  • Some days..... MOS...this bug's for you
Re: Malware/Trojans
« Reply #43 on: July 31, 2012, 09:18:42 AM »
Hi JackSession,

This seems to be a known problem with FireFox since FireFox went to html5.
Quote
There are two solutions to the choppy videos problem (for Firefox users).

1.) I simply don't watch YouTube videos on Firefox anymore. Switch to Internet Explorer. The reason is that Firefox has apparently switched to this new technology called html5 and have shifted away from Java.
http://www.examiner.com/article/how-to-fix-choppy-problematic-videos-on-youtube-firefox-users

 YouTube has some suggested fixes.
http://support.google.com/youtube/bin/answer.py?hl=en&answer=74662

Here's one that relates to FF's habit of saving the tabs every 10 seconds.
http://lifehacker.com/5342636/how-to-fix-annoying-youtube-jumpiness-in-firefox

I would try this one. In FireFox's address bar copy and paste about:config and hit enter. If you see a page with the warning message, This might void your warranty!, click the button labeled "I'll be careful, I promise!", to continue. (don't worry they're not serious.)

Scroll down to browser.sessionstore.interval
  • right click it and click modify
    enter 300000 in the box and click ok
close the tab

It seems Flash is a problem with audio
http://support.mozilla.org/en-US/questions/929872#answer-343540
« Last Edit: July 31, 2012, 12:08:49 PM by oldman »

JackSession

  • Guest
Re: Malware/Trojans
« Reply #44 on: July 31, 2012, 11:00:42 PM »
thanks oldman..i know its kind of off topic and this info really helped..it was because of the new flash player being installed...i uninstalled it and installed flash 10 and no problems at all...im not sure if this would present potential security issues but either way i think ill reinstall the newest flash player and just use IE

Thanks!!
Jack :)