Author Topic: Virus and Malware.. after clean up of Ransomware... what next?  (Read 21480 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #15 on: November 04, 2014, 08:26:40 PM »
Yes allow a reboot as it will need to finish prior to windows loading

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #16 on: November 04, 2014, 09:23:59 PM »
OK -- did Restart then ran AdwCleaner and all seems to be back to normal.. THANKS!

Is there any final scan/check that will confirm all is now OK?

Are you able to explain briefly what was wrong and what has been corrected?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #17 on: November 04, 2014, 09:53:39 PM »
The remnant was a change to Chrome that would allow unsigned files to run otherwise it was just a matter of clearing the junk files :)

Subject to no further problems   :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems 

Now the best part of the day ----- Your log now appears clean  :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset  System Restore points:

Download and run Delfix




: Keep Java Updated :

WARNING: Java is the #1 exploited program at this time. The Department of Homeland Security recommends that computer users disable Java
See this article

I would recommend that you completely uninstall Java unless you need it to run an important software.
In that instance I would recommend that you disable Java in your browsers until you need it for that software and then enable it. (See How to diasble Java in your web browser and How to unplug Java from the browser)

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:

CryptoPrevent install this programme to lock down and prevent crypto ransome ware



Malwarebytes.

Update and run weekly to keep your system clean


It is critical to have both a firewall and anti virus to protect your system and to keep them updated.

To learn more about how to protect yourself while on the internet read this little guide  Best security practices Keep safe  :wave:

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #18 on: November 04, 2014, 10:00:38 PM »
DOUBLE BRILLIANT THANKS essexboy...................  I will run all that and post confirmation.

Over and OUT for today   :)

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #19 on: November 05, 2014, 11:29:37 AM »
OK, finally I think it's all done.

The repair of Action Centre Security worked until a reboot then the problem returned.   I then used this fix from MS Community (because the error code I saw was 126):

http://answers.microsoft.com/en-us/windows/forum/windows_xp-windows_programs/windows-management-instrumentation-error-code-126/1202e348-5964-e011-8dfc-68b599b31bf5
 
>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

Method 1

You may follow these steps and check if the issue persists.

a. Click Start -> Type CMD -> Right click on CMD from the result -> Click Run as Administrator

b. Run the following command one at a time and press enter to execute (without the dot before the code and take care of spaces)

• cd /d %windir%\system32\wbem

• for %i in (*.dll) do regsvr32 -s %i

• for %i in (*.exe) do %i /regserver

c. Close all windows and reboot the computer and now try opening the system information

This above fix Method 1 worked and has stayed fixed.

>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>>

I ran DELFIX exactly as you advised.

I completely uninstalled Java

I have also set my account as Standard User and set a new Aministrator account.

CryptoPrevent is downloaded and installed but it seemed to need installing in both my User account and in the Admin account.. is that right? Also I can not find it anywhere in Programmes or Task manager under Processes or Services unless CryptSvc - Cryptographic Services - Network Service is CryptoPrevent?  Also, I suppose it makes sense to purchase the Premium to get updates?

Windows Defender and Windows Firewall are no longer running ..... Does MalwareBytes and/or Avast provide a Firewall?

I look forward to receiving clarification of the above points please.

After so many years using PCs this episode has once again shown me how little expertise I really have...   THANKS AGAIN!!!
« Last Edit: November 05, 2014, 11:32:39 AM by cridgejm »

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #20 on: November 05, 2014, 12:30:30 PM »
Paid versions of Avast! give you a Firewall, Free does not (So you don't get one from Avast!)

There are many free Firewalls out there. I use Comodo FW, but have heard decent things about ZoneAlarm and Online Armo(u)r.

http://www.online-armor.com/
http://www.personalfirewall.comodo.com/
http://www.zonealarm.com/security/en-us/zonealarm-pc-security-free-firewall.htm

Edit: Answered my own question :)

« Last Edit: November 05, 2014, 12:35:00 PM by Michael (alan1998) »
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #21 on: November 05, 2014, 12:57:44 PM »
Thanks for that Michael.

Rather than introduce a third security software (fourth with CryptoPrevent) I wonder whether it may be better to move to Avast Internet Security with Firewall?

Advice?  Michael, essexboy, anyone?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #22 on: November 05, 2014, 01:03:37 PM »
...I wonder whether it may be better to move to Avast Internet Security with Firewall?
Sure, why not... ;)
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #23 on: November 05, 2014, 01:17:14 PM »
Thanks for that Michael.

Rather than introduce a third security software (fourth with CryptoPrevent) I wonder whether it may be better to move to Avast Internet Security with Firewall?

Advice?  Michael, essexboy, anyone?

I don't think it'll make a HUGE difference. The reason why I do it with Comodo, MBAM, Avast!, Unchecky, MCSHield etc is because if 1 falls, the others remain. Just my personal preference, and my computer can handle all the programs I run (i7 3770, 16GB of RAM and a 2TB drive is more then enough)
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #24 on: November 05, 2014, 01:44:03 PM »
What I am concerned about is conflict between so many security pieces?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #25 on: November 05, 2014, 01:57:06 PM »
What I am concerned about is conflict between so many security pieces?
My personal opinion is, that for average users a suite will fit well, advanced users can go with Michael's setup.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #26 on: November 05, 2014, 02:49:00 PM »
What I am concerned about is conflict between so many security pieces?
My personal opinion is, that for average users a suite will fit well, advanced users can go with Michael's setup.

Agreed.

I have mine setup that way for various reason aside from, if 1 falls the rest remain. For you, I'd just go with the Suite. Avast! paid, MBAM should be fine.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #27 on: November 05, 2014, 05:02:43 PM »
Cryptoprevent does not run it just makes changes to the registry so you will not see any processes :)

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #28 on: November 05, 2014, 06:02:59 PM »
Thanks for the Crypto clarification EB.

Should I use the PAID version in order to get updates?
[/b]

sorry, didn't mean to shout.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #29 on: November 05, 2014, 06:03:47 PM »
I don't think it's needed. Just every once in a while, update it manually.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.