Author Topic: Custom scan revealed threats in memory  (Read 12407 times)

0 Members and 2 Guests are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Custom scan revealed threats in memory
« Reply #15 on: February 22, 2013, 03:14:48 PM »
Quote
O1 - Hosts: 127.0.0.1   www.007guard.com
O1 - Hosts: 127.0.0.1   007guard.com
O1 - Hosts: 127.0.0.1   008i.com
O1 - Hosts: 127.0.0.1   www.008k.com
These are entered either by Spybot or MSVP hosts file..  However if you update to IE9 they are no longer required http://www.microsoft.com/en-us/download/details.aspx?id=16792  especially with webshield.  It is basically a block on entering those sites

Quote
"File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot." - is this file part of avast??
yes it is an Avast temporary file

For Firefox you can use Adblock  https://addons.mozilla.org/en-US/firefox/addon/adblock-plus/

Quote
I remember reading somewhere on a anti virus website that a lot of infections use java to penetrate your system so bearing that in mind I don't think my java has been updated for ages should I update it?
Unless you really need Java then uninstall it

Quote
I use Avast Free, MBAM free(to be honest I wasn't using it regularly) and Spybot search and destroy and Windows Firewall turned on, are there any products that you would recommend to use in addition or to replace the ones I have been using?
Spybot is a bit of an overkill with the Avast/MBAM combo 

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Run OTL and hit the cleanup button.  It will remove all the programmes we have used plus itself. 

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Click Start.
  • Open My Computer.
  • Select the Tools menu and click Folder Options.
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.
: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article and this article.
I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

Malwarebytes.

Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

If you use on-line banking then as an added layer of protection install Trusteer Rapport

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit To learn more about how to protect yourself while on the internet read our little guide  How did I get infected Keep safe  :wave:

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #16 on: February 22, 2013, 03:45:04 PM »
OK you quoted those hosts what about the ones that have weird names such as:100sexlinks.com(Where did this come from, i doubt this is something spybot or MSVP use).

Do you use IE9 instead of firefox? and is it better?

I know this sounds a bit silly but isn't java needed to watch videos and play games on computers?

This probably make me silly ;), a friend of mine who I knew years ago, was a programmer told me not to use Microsoft update as he says they just put things to spy on your computer. So I haven't used the update feature for years, should I?

One thing that would be interesting to know is your computer spec and protection as I have seen others post that information just to see if people like me are more vulnerable because of software and hardware or other factors??

Thanks for all your help Essex boy I hope in 24 hours I don't have to come back. :)

Ohhh I almost forgot I was looking in my virus vault and saw this:
Name: ADMIN_CLASS_LIB.dll
Original Location: C:\Windows\System32
Last changed: 13/04/2007 00:40:22
Transfer time: 28/05/2012 02:23:24
Virus: Win32:Trojan-gen

Is this actually a virus???


RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #18 on: February 22, 2013, 04:23:29 PM »
Thanks Pondus.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Custom scan revealed threats in memory
« Reply #19 on: February 22, 2013, 04:33:08 PM »
Quote
a friend of mine who I knew years ago, was a programmer told me not to use Microsoft update as he says they just put things to spy on your computer.
He is talking through the back of his head... Updates are vital for windows as they will close security holes ..  So turn it on

Quote
One thing that would be interesting to know is your computer spec and protection
I have one computer running XP, 7 and 8 (different partitions) And I use Avast Internet Security and ..........  Common sense, that's it 
I also have IE10 as I feel IE from 9 onwards is more secure than any other browser

I do not have Java on my system and never have

Offline DavidR

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 89168
  • No support PMs thanks
Re: Custom scan revealed threats in memory
« Reply #20 on: February 22, 2013, 05:10:34 PM »
Quote
a friend of mine who I knew years ago, was a programmer told me not to use Microsoft update as he says they just put things to spy on your computer.

He is talking through the back of his head... Updates are vital for windows as they will close security holes ..  So turn it on
<snip>

Your being far to polite again, I would have thought he was talking through another part of his anatomy, somewhat further south ;D
Windows 10 Home 64bit/ Acer Aspire F15/ Intel Core i5 7200U 2.5GHz, 8GB DDR4 memory, 256GB SSD, 1TB HDD/ avast! free 24.4.6112 (build 24.4.9067.762) UI 1.0.803/ Firefox, uBlock Origin, uMatrix/ MailWasher Pro/ Avast! Mobile Security

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #21 on: February 22, 2013, 07:50:03 PM »
 ;D Well it was a long time ago, I will turn on updates later tonight as there will be too many to add right now and I need my computer for work. Thanks you for all your help (everyone ;D). Hopefully everything will be fine now

Does anyone have an idea about these two problems??
1.
Quote
OK you quoted those hosts what about the ones that have weird names such as:100sexlinks.com(Where did this come from, i doubt this is something spybot or MSVP use).

2.
Quote
Ohhh I almost forgot I was looking in my virus vault and saw this:
Name: ADMIN_CLASS_LIB.dll
Original Location: C:\Windows\System32
Last changed: 13/04/2007 00:40:22
Transfer time: 28/05/2012 02:23:24
Virus: Win32:Trojan-gen

Is this actually a virus???


Thank you

Rish

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Custom scan revealed threats in memory
« Reply #22 on: February 22, 2013, 07:53:10 PM »
The host file is full of bad links but as they point to 127.0 then they are going nowhere, they are the spybot immunisation links which it placed there.  They are not a problem

ADMIN_CLASS_LIB.dll is probably a false positive as it relates to Acer software

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #23 on: February 22, 2013, 10:34:53 PM »
Great thanks for all the help.. ;)

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #24 on: February 22, 2013, 11:43:38 PM »
Hi again I wish I didn't have to come back here but unfortunately that's not the case. I decided to run a boot scan with avast but the scan was being very slow it took 40 minutes to reach 8% so by that logic it would have taken 4 1/2 hours to complete. It was finding problems anyway so I ended the scan prematurely as I wanted to double check something, could you have a look at the results and tell me if I have to be worried by the Zbot [Trj].

Thanks in advance

Rish

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #25 on: February 23, 2013, 11:59:40 AM »
Hi can anyone help with this problem :-\
Quote
Hi again I wish I didn't have to come back here but unfortunately that's not the case. I decided to run a boot scan with avast but the scan was being very slow it took 40 minutes to reach 8% so by that logic it would have taken 4 1/2 hours to complete. It was finding problems anyway so I ended the scan prematurely as I wanted to double check something, could you have a look at the results and tell me if I have to be worried by the Zbot [Trj].

Thanks in advance

Rish

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76035
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Custom scan revealed threats in memory
« Reply #26 on: February 23, 2013, 12:07:35 PM »
Hi can anyone help with this problem :-\

Please be patient, it's weekend. ;)
Essexboy will be around later today.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Custom scan revealed threats in memory
« Reply #27 on: February 23, 2013, 12:15:56 PM »
C:\Users\Martin\AppData\Local\Microsoft\Windows\WER\ReportQueue this is the location for windows error reports and may well be a false positive, as to the best of my knowledge no malware runs from that location...  And the files are error dump reports

RishR

  • Guest
Re: Custom scan revealed threats in memory
« Reply #28 on: February 24, 2013, 04:53:47 AM »
Thank you, well is it still OK to delete those reports anyway just to be safe or will that cause some disruption to my computer?

Cheers Essexboy, Asyn, Pondus and everyone else on this forum for your help ;D

Rish

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Custom scan revealed threats in memory
« Reply #29 on: February 24, 2013, 12:45:09 PM »
They can be deleted with no harm