Author Topic: Unknown Virus Issues, Network Connection Problems  (Read 4102 times)

0 Members and 1 Guest are viewing this topic.

Atani

  • Guest
Unknown Virus Issues, Network Connection Problems
« on: November 12, 2010, 06:02:45 AM »
(I'm having to retype this again...I F5'd when I meant to type "F5"...I feel stupid and frustrated)

First, random bit: I should be getting paid to do this, fixing all of my friends computers. I do this too much >_>
Then again, so should essexboy and everyone else on here who does a fantastic job helping us guys out lol

Second, about the computer involved: Laptop running Windows Vista Basic, Outdated Avira antivirus, Windows Defender that won't update.

Third, the troubles at hand: I just moved in with a couple friend, new appartment, new wireless router, new password. I was trying to set up the wireless connection on this laptop, but the laptop started turning off its internal wireless card. (Usually that requires pressing Fn+F5, also, this is how far I was typing this out when I accidentally refreshed the page...extra careful this time).

Also I couldn't figure out how to enter the network password, eventually I got it to work. I'm not sure if that's my fault, or the computers  ::).

Certain web pages won't load, either. For example, the first link to MBAM in essexboy's malware removal step-by-step post wasn't loading, and neither would Avira antivirus's website...both are loading now, though.

When I downloaded MBAM, I noticed that Windows also copied a file to the desktop simultaneously, a alphanumeric string, though when I looked, it wasn't there. I couldnt' tell where it was copied from, either. This happened again when I downloaded OTL. I deleted my MBAM install file and downloaded it again, to try to get more info on what was being copied. Its a different string of text each time, somewhere around 8 characters long. I still couldn't tell where it was coming from, it disappeared within about 2 seconds and the file path was truncated.

I haven't had more than about an hour to spend looking this laptop over, and I'm worried about running MBAM or OTL might be unsafe (because of the files Windows was copying when I downloaded MBAM and OTL). I can get MBAM and OTL with another computer to be in the safe side.

And as for having Avira: This is his laptop, not mine. It'd already have avast! on it if it were mine. And MBAM.

(This is why I like Ubuntu  :P)

Thanks in advance.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unknown Virus Issues, Network Connection Problems
« Reply #1 on: November 12, 2010, 12:36:00 PM »
Lets have a look see  ;D

Download OTS to your Desktop and double-click on it to run it
  • Make sure you close all other programs and don't use the PC while the scan runs.
  • Select All Users
  • Under additional scans select the following
Reg - NetSvcs
Reg - Shell Spawning
Evnt - EventViewer Logs (Last 10 Errors)
File - Lop Check
File - Purity Scan


  • Now click the Run Scan button on the toolbar. Make sure not to use the PC while the program is running or it will freeze.
  • When the scan is complete Notepad will open with the report file loaded in it.
  • Please attach the log in your next post.

Atani

  • Guest
Re: Unknown Virus Issues, Network Connection Problems
« Reply #2 on: November 12, 2010, 11:22:37 PM »
Is it safe to download it and run if from that laptop, or should I download it on my computer and transfer it from a usb drive?

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unknown Virus Issues, Network Connection Problems
« Reply #3 on: November 13, 2010, 12:02:32 PM »
It is a safe programme - download to the infected system

Atani

  • Guest
Re: Unknown Virus Issues, Network Connection Problems
« Reply #4 on: November 15, 2010, 06:44:09 PM »
It is a safe programme - download to the infected system

I know the program is safe, lol.
I meant is it safe to download the files with this laptop, and run said downloaded files, taking this into consideration:

When I downloaded MBAM, I noticed that Windows also copied a file to the desktop simultaneously, a alphanumeric string, though when I looked, it wasn't there. I couldnt' tell where it was copied from, either. This happened again when I downloaded OTL. I deleted my MBAM install file and downloaded it again, to try to get more info on what was being copied. Its a different string of text each time, somewhere around 8 characters long. I still couldn't tell where it was coming from, it disappeared within about 2 seconds and the file path was truncated.

Because:

I haven't had more than about an hour to spend looking this laptop over, and I'm worried about running MBAM or OTL might be unsafe (because of the files Windows was copying when I downloaded MBAM and OTL). I can get MBAM and OTL with another computer to be in the safe side.

Do you understand what I mean/why I'm asking? I honestly don't know how most viruses work, but is it possible that an infected computer could infect newly downloaded files for the purpose of sustaining itself? By spreading its code around, I mean. That seems like a rather crafty and possibly effective way of spreading a vius, infecting as many files as possible, especially .exe's.

I mean, it's not normal for this laptop to be copying random-named files to the desktop every time I download something off the net, right. I know I don't use Vista terribly often, but that seems...suspicious.

I'm going to assume I should go ahead and run those files, I'm probably just being paranoid  ;D

EDI: I downloaded MBAM and OTL in advance before you posted in this thread, I haven't ran them yet. Is OTS a newer version of OTL, or is it an entirely different program? (The GUI seems similar, just wondering)
Running OTS as soon as I close this window.
« Last Edit: November 15, 2010, 06:50:47 PM by Atani »

Atani

  • Guest
Re: Unknown Virus Issues, Network Connection Problems
« Reply #5 on: November 15, 2010, 07:09:36 PM »
I noticed that OTS defaults to files newer than 30 days.
I don't know how long this computer has been infected (assuming it is infected at all).
I do know that this laptop gets very little use, and hasn't been online much since back in...July maybe

OTS log is attached.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Unknown Virus Issues, Network Connection Problems
« Reply #6 on: November 15, 2010, 09:26:50 PM »
OTS is a different version of OTL a tad more powerfull

Download Dr Web from here http://www.freedrweb.com/?lng=en link on the top right of the page, tick the EULA and then download
 
It will download as an 8 digit file save it to your desktop

Restart in safe mode and run
Accept the enhanced version
Then run the quick scan
About halfway through you will be prompted to buy - just X the box closed
Once finished it will generate a log please attach that