Jump to content

JeanInMontana

Honorary Members
  • Posts

    3,859
  • Joined

  • Last visited

Posts posted by JeanInMontana

  1. Yes, you need to turn it on. If you uncheck it shuts it off. You want your system to keep making restore points on it's own too.

    Now go to Start>Help and Support > Undo Changes to Your System or System Restore depending on the make of your PC. Click on what ever will open the System Restore box. You will see two options, Choose Create a System Restore Point. Give it a name like Clean Restore Point and today's date. Now if you need to use it you have it.

    Since this issue is resolved I will close the thread to prevent others from posting into it. If you need assistance please start your own topic and someone will be happy to assist you.

    The fixes and advice in this thread are for this machine only. Do not apply to your machine. Please start a thread of your own and someone will be happy to help you.

  2. Hi Jerry2008 and welcome to Malwarebytes.

    Please set your system to show

    all files; Click Start.

    Open My Computer.

    Select the Tools menu and click Folder Options.

    Select the View Tab.

    Under the Hidden files and folders heading select Show hidden files and folders.

    Uncheck the Hide protected operating system files (recommended) option.

    Click Yes to confirm.

    Click OK.

    Please find these files C:\WINDOWS\system32\xrxbeacn.exe; and and attach it in a zipped folder here in a new topic you start, link back to your thread here in the HJT forum please. It's very important you link back to this thread so the researchers see why they are looking at that file.

  3. Hi SimonF and welcome to Malwarebytes. Please move HJT to it's own folder on C:\Program files.

    Did you make this change R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = ARSENAL ARE THE BEST ?

    Please run HJT in scan only and put a check next to the following items.

    O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

    O20 - AppInit_DLLs:

    O23 - Service: BCL easyPDF SDK Loader (ogidu15uynijoxoe) - Unknown owner - C:\WINDOWS\system32\kunoobapyg.exe (file missing)

    Reboot to normal mode. Update MBAM run a quick scan, post that log and a new HJT log please.

  4. Well your ghosted image is infected also. When I say reformat I mean wipe the disk. Total reinstall. Do you have the install disks? That is what you need to use, then ghost when you have updated all Windows updates, and installed your software etc.

    As far as contacting my banks and credit card companies, is there any specific that I should say to them other than my accounts might be compromised since my personal information might have been hacked on my pc???? I new to this as far as personal experience goes and any recommendations are greatly appreciated.

    You need to tell them the passwords need changed, any charges, withdrawals ect might not be you. Identity theft is a well known issue with banks and credit cards. They will know how to handle it but notify them now.

  5. No worries, it can just cause problems if your doing stuff I don't know about.

    Your log looks clean. We need to now reset a clean System Restore point. If you don't and you need to use System Restore you will reinfect yourself. Go to Start>Control Panel>System. Click on the System Restore tab and put a check in Turn off System Restore. Then click OK.

    Now go to Start>Help and Support > Undo Changes to Your System or System Restore depending on the make of your PC. Click on what ever will open the System Restore box. You will see two options, Choose Create a System Restore Point. Give it a name like Clean Restore Point and today's date. Now if you need to use it you have it.

    Many infections can be avoided with an added layer of prevention. All recommended programs are free and easy on system resources. You should install them as part of your protection arsenal. Keep MBAM and Spybot Search & Destroy and always immunize SBS&D when you update. You will also need at least one other scanning program Asquared or SuperAntiSpyware are good and there are several other excellent programs with free and paid versions. Read the overviews of what each program below does so you have an understanding of their importance and how to use.

    A firewall and antivirus are also essential. The Windows firewall in XP and Vista is not sufficient.

    Preform Windows Updates monthly on the second Tuesday or use automatic updates, and use your scanners weekly at the least. Always update before you scan.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    SpywareBlaster from Javacool Software

    WinPatrol by BillPStudios

    SiteHound by FireTrust

    RogueRemover

    hpHosts

    The windows firewall is not sufficient to protect. It doesn't monitor outgoing traffic and this is a must. I use and recommend Online Armor Free

    Also the full protection of MBAM is offered at a very low price, from the link in my signature.

  6. Yay! OK, you should post about the System Restore in PC Help, and see if someone can help there, or do some Google searches.

    You are running an outdated and unsafe version of Java. You must fix this. You need to uninstall it via Add/Remove programs and delete the program file also. Then go here Java Update and install the correct version for your system. Choose the offline installation.

    Many infections can be avoided with an added layer of prevention. All recommended programs are free and easy on system resources. You should install them as part of your protection arsenal. Keep MBAM and Spybot Search & Destroy and always immunize SBS&D when you update. You will also need at least one other scanning program Asquared or SuperAntiSpyware are good and there are several other excellent programs with free and paid versions. Read the overviews of what each program below does so you have an understanding of their importance and how to use.

    A firewall and antivirus are also essential. The Windows firewall in XP and Vista is not sufficient.

    Preform Windows Updates monthly on the second Tuesday or use automatic updates, and use your scanners weekly at the least. Always update before you scan.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    SpywareBlaster from Javacool Software

    WinPatrol by BillPStudios

    SiteHound by FireTrust

    RogueRemover

    hpHosts

    The windows firewall is not sufficient to protect. It doesn't monitor outgoing traffic and this is a must. I use and recommend Online Armor Free

    Also the full protection of MBAM is offered at a very low price, from the link in my signature.

  7. Since this issue is resolved I will close the thread to prevent others from posting into it. If you need assistance please start your own topic and someone will be happy to assist you.

    The fixes and advice in this thread are for this machine only. Do not apply to your machine. Please start a thread of your own and someone will be happy to help you.

  8. I just wanted to check and make sure that after purchasing, Weather i will recieve future version updates.

    Or if i'll have to purchase again after a year or a new and improved version of the mailware software comes out.

    May be a stupid question but not asking things like this has cost me with other software in the past.

    Hi Genmu and welcome to Malwarebytes. No it's not a stupid question. Lots of companies charge yearly for renewals. MBAM is a lifetime license with all future updates included in that. The current version is the 30th since its public release nearly a year ago.

  9. This is a post for a member from another forum.

    Therefore I can't submit a log or upload of this possible false positive.

    I thought you might like to see it anyway.

    C:\WINDOWS\system32\mst120.dll

    What's stopping them from joining and posting their own logs? Second hand is usually of no use to anyone.

  10. Like I said MBAM is not the root of the security risk in the Active Desktop. The active desktop is the risk. Turn it off. Do not allow the active desktop to run and install etc. That is the risk.

    MBAM does not have an auto update at boot feature. You need to choose a time and that is when it will update. Have you set your firewall to allow MBAM? What firewall do you use? I don't know what error message your getting a screen shot would be helpful.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.