Author Topic: Virus and Malware.. after clean up of Ransomware... what next?  (Read 21550 times)

0 Members and 1 Guest are viewing this topic.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #30 on: November 05, 2014, 06:46:27 PM »
Weekly should suffice with a manual update

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #31 on: November 05, 2014, 07:17:52 PM »
Yet it's only $15 for 'Premium' with auto updates etc....  have paid but will download later.

Ah, no need to download just to enter Product Key.. so all done with CryptoPrevent...  Worth $15 not to have to remember to update.


AND Komodo Firewall now installed .. all seems to be working OK.


BUT Komodo did find a folder Tific which had no active files in it... date loaded showed as 2 Nov, the date the ransomware kicked in... maybe Tific was the empty remains of that infection?

Now only 2 Unknown files showing on Komodo Scan:

cfrmd.sys  and  mahostservoce.exe...............    cfrmd shows as Komodo     Mahostservice shows as Alcatel-Lucent

They both seem OK?  I should mark them as 'Trust' in Komodo?
« Last Edit: November 05, 2014, 08:56:48 PM by cridgejm »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #32 on: November 05, 2014, 09:13:19 PM »
cfrmd.sys  this is from Comodo

mahostservoce.exe did you mean mahostservice.exe

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #33 on: November 05, 2014, 09:16:44 PM »
yes, service................


BUT now, since installing Komodo ebay website is running jerky... when scrolling down or going to next page... any ideas?

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #34 on: November 05, 2014, 09:20:22 PM »
Komodo or Comodo?

Komodo would be fake, Comodo is real..

Never had that issue before. I do know though, that issue is present on all of my school computers (The ones owned by the government,)

What browser are you using? I'll look into it.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #35 on: November 05, 2014, 09:26:04 PM »
Oh dear, it's time for bed...  yes COMODO  (was dreaming of dragons) .................  browser Int Exp 10.

AND I have found several reports of Comodo-Avast conflict.

So... I will now uninstall Comodo and pay for Premium Avast...................   am I a dipstick?  I think so!


OK.. done... Comodo all gone................ Avast upgraded £49 paid for 2 years max 3 pcs.

All seems OK . watch this space!
« Last Edit: November 05, 2014, 09:57:29 PM by cridgejm »

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #36 on: November 05, 2014, 09:59:10 PM »
I have used AIS since it was first released and have had no problems from Vista to windows 8.1 :)

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #37 on: November 05, 2014, 10:19:19 PM »
Oh dear, it's time for bed...  yes COMODO  (was dreaming of dragons) .................  browser Int Exp 10.

AND I have found several reports of Comodo-Avast conflict.

So... I will now uninstall Comodo and pay for Premium Avast...................   am I a dipstick?  I think so!


OK.. done... Comodo all gone................ Avast upgraded £49 paid for 2 years max 3 pcs.

All seems OK . watch this space!


Did you have D+ installed aswell? I believe I warned you via PM not to install D+ with Comodo Firewall.
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #38 on: November 06, 2014, 01:13:03 AM »
My Avast internet started saying internet connection not connected so i phoned what i thought was Avast, the guy took over my computer and told me my PC was infected with virus's, as i'm inexperienced  with computers i started to panic, he was saying my PC would stop and cause me all kinds of headaches. he told me it would cost £129 for 12 months then started telling me about a deal for 2 years, i told him 12 months, he told me he worked for Avast and i had the full Avast support behind me, i was 9 months into a 12 months licence and thinking it was Avast i thought it would be OK. he was on the PC for about 4 hours then someone else took over for 1 hour more. that night the computer stopped working, after 2 hours it started working again , then i lost me gmail and had to phone them up. i found out they were based in Costa Rica, over the next couple of days my PC went down 5 or 6 times, then i get a email telling me there was a problem with the billing and to send them my bank details so they could put money back into account, but i had paid with Paypal, when i phoned up they told me they didn't know what i was talking about and should ignore the email, they didn't seem put out at all. sorry the company is called Avast total support, this only happened on the 29th October and the email for my bank account was sent on the 1st November, the email had all my details? i decided to look on this forum and there where lots of people complaining that this company is 3rd party but says it's Avast, i even sent a email to avast about this and got a reply from them. Sandra Richard | avast! Total Support Escalations – Customer Care | avast!, i haven't got a problem with Avast ,in fact i just bought a 3 year Avast premier even though i had 3 months left on my old Avast, even if you look at their website it looks like it is Avast, because i don't know anything about computers i'm thinking what have they done on my PC. I think they where reading your website and replying to me like they where you when one of the people on your forum gave me a email address. can you help.

Offline Michael (alan1998)

  • Massive Poster
  • ****
  • Posts: 2768
  • Volunteer
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #39 on: November 06, 2014, 02:21:46 AM »
Jonny, what I meant was start your own thread -_-.

Regardless, I'm sure Essex will help you here.

Start by following the guide: https://forum.avast.com/index.php?topic=53253.0
VOLUNTEER

Senior Security Analyst; Sys Admin (Linux); Forensics/Incident Response.

Security is a mindset, not an application. Think BEFORE you click.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #40 on: November 06, 2014, 08:38:38 AM »

Did you have D+ installed aswell? I believe I warned you via PM not to install D+ with Comodo Firewall.

No, D+ not installed.. had to Google to know what it is  :)

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #41 on: November 06, 2014, 10:06:37 AM »




Jonny, Michael is right - start a new thread .... essexboy has been extremely helpful to me

I will also be contacting Avast regarding misrepresentation of Tech Support and not full clearance of the problems on my PC.  I will be seeking a cancellation of the 1 year Tech Support contract (via Avast an UK MasterCard) and will then donate £50 to the charity of choice of essexboy (I'll post the receipt here).
« Last Edit: November 06, 2014, 10:09:39 AM by cridgejm »

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #42 on: November 08, 2014, 08:30:36 PM »
After all that (see thread) MWB tells me I have problem with qfWY.dll.  It shows as Trojan.Agent.DE 


I attach FRST files: FRST and Addition


Thanks in advance to my Guardian Angel..............   
 

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #43 on: November 08, 2014, 08:52:16 PM »
Could you post MBAM's log please as there is nothing untoward showing

Download and run farbar service scanner



Tick "All" options.
Press "Scan".
It will create a log (FSS.txt) in the same directory the tool is run.

Please copy and paste the log to your reply.

REDACTED

  • Guest
Re: Virus and Malware.. after clean up of Ransomware... what next?
« Reply #44 on: November 08, 2014, 09:31:42 PM »
MWB attached.  willco the other.