Jump to content

JeanInMontana

Honorary Members
  • Posts

    3,859
  • Joined

  • Last visited

Posts posted by JeanInMontana

  1. I have a question about this. My wife was surfing the internet and was trying to post some photos to myspace, while using our MacBook. Some sort of a pop-up appeared from one of these sites (scan.scannerantispyware.com). It threatened someone had stolen information and it needed to download something. It automatically started downloading some sort of text file to our computer. She tried to close the site and it wouldn't close. She then deleted the files as soon as she could. Do we have any reason to be worried? Could that have stolen any information we may have saved into our computer?

    I would suggest you have some logs looked at it's very likely your infected. Follow the instructions here http://www.malwarebytes.org/forums/index.php?showtopic=2936 and start your own topic in that forum.

  2. Aww thanks. Be sure you add some prevention stuff to the machine to avoid this in the future.

    Many infections can be avoided with an added layer of prevention. All recommended programs are free and easy on system resources. You should install them as part of your protection arsenal. Keep MBAM and Spybot Search & Destroy and always immunize SBS&D when you update. You will also need at least one other scanning program Asquared or SuperAntiSpyware are good and there are several other excellent programs with free and paid versions. Read the overviews of what each program below does so you have an understanding of their importance and how to use.

    A firewall and antivirus are also essential. The Windows firewall in XP and Vista is not sufficient.

    Preform Windows Updates monthly on the second Tuesday or use automatic updates, and use your scanners weekly at the least. Always update before you scan.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    SpywareBlaster from Javacool Software

    WinPatrol by BillPStudios

    SiteHound by FireTrust

    RogueRemover

    hpHosts

    The windows firewall is not sufficient to protect. It doesn't monitor outgoing traffic and this is a must. I use and recommend Online Armor Free

    Also the full protection of MBAM is offered at a very low price, from the link in my signature.

  3. I am so sorry for not replying to you, I think I must not have checked to get an email notice. So how is it running? Logs look good, did the file delete with Killbox?

    Run HJT in scan only and put a check next to the following and then click fix.

    O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

    O23 - Service: QRCNOD - Unknown owner - C:\DOCUME~1\Edward\LOCALS~1\Temp\QRCNOD.exe (file missing)

    O23 - Service: YLX - Unknown owner - C:\DOCUME~1\Edward\LOCALS~1\Temp\YLX.exe (file missing)

    Reboot and lets get another GMER log

    OK let's go for another special scan tool.

    Download GMER get the zip file and save to your desktop.

    Just run gmer.exe. All required files ( gmer.dll and gmer.sys ) will by copied to the system during the first lanuch. .

    Do not click scan.Use the copy button to copy to your clipboard. Post the log in your next reply.

  4. How are things running now?

    Run HJT in scan only and mark the following be sure to click fix.

    O2 - BHO: Iterasi.IEPlugin.Bar.InitToolbarBHO - {b21973d1-cbd6-46a8-8fcb-2af7aaaeb9ae} - mscoree.dll (file missing)

    O3 - Toolbar: iterasi Toolbar - {8e0c19a9-5657-409b-953f-59c941ffba4e} - mscoree.dll (file missing

    Reboot

    Be sure Java and Adobe are updated.

    If you feel your system is clean then proceed to the next steps.

    Your log looks clean. We need to now reset a clean System Restore point. If you don't and you need to use System Restore you will reinfect yourself. Go to Start>Control Panel>System. Click on the System Restore tab and put a check in Turn off System Restore. Then click OK.

    Now go to Start>Help and Support > Undo Changes to Your System or System Restore depending on the make of your PC. Click on what ever will open the System Restore box. You will see two options, Choose Create a System Restore Point. Give it a name like Clean Restore Point and today's date. Now if you need to use it you have it.

    Many infections can be avoided with an added layer of prevention. All recommended programs are free and easy on system resources. You should install them as part of your protection arsenal. Keep MBAM and Spybot Search & Destroy and always immunize SBS&D when you update. You will also need at least one other scanning program Asquared or SuperAntiSpyware are good and there are several other excellent programs with free and paid versions. Read the overviews of what each program below does so you have an understanding of their importance and how to use.

    A firewall and antivirus are also essential. The Windows firewall in XP and Vista is not sufficient.

    Preform Windows Updates monthly on the second Tuesday or use automatic updates, and use your scanners weekly at the least. Always update before you scan.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    SpywareBlaster from Javacool Software

    WinPatrol by BillPStudios

    SiteHound by FireTrust

    RogueRemover

    hpHosts

    The windows firewall is not sufficient to protect. It doesn't monitor outgoing traffic and this is a must. I use and recommend Online Armor Free

    Also the full protection of MBAM is offered at a very low price, from the link in my signature.

  5. Hi all,

    I'm Ltangelic, and I'm also a fellow graduate from GeekU like Transience is. :blink: I'm currently a malware staff over at G2G and a volunteer helper at Lavasoft forums. Nice to meet you guys and hope I can contribute and learn more here! :blink:

    LT

    16.gif Hi great to have you here!

  6. OK let's try this don't worry about trying to install the recovery console you won't be able to if you don't already have it. Just try to run this and get the log posted.

    Review this article here how to use ComboFix

    Be sure you cover the section on How to install and use the Windows XP Recovery Console and make sure it is installed on your machine. This is important should anything go wrong and we need to recover your PC and not lose all the data.

    1. Download this file :

    http://download.bleepingcomputer.com/sUBs/ComboFix.exe save it to your desktop.

    2. Double click combofix.exe. It will be a red icon with a white X on your desktop.

    Follow the prompts you will get a blue cmd prompt screen and a choice to choose Y or N. Choose Y and hit enter.

    3. When finished, it shall produce a log for you. This logfile is located at C:\ComboFix.txt.

    Post that log and a HiJack log in your next reply

    Note:

    Do not mouseclick combofix's window while its running. That may cause it to stall.

  7. Yippeee!! OK now some other major uninstalling and updates are crucial. But first run HJT again in scan only put a check next to each line and click fix.

    O4 - HKLM\..\Run: [userFaultCheck] %systemroot%\system32\dumprep 0 -u

    O4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Testfolder\mbam.exe" /runcleanupscript <===== what's up with that?

    O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

    Reboot

    Uninstall Java from Add/Remove programs You have an ancient version also uninstall Viewpoint and Adobe reader.

    You are running an outdated and unsafe version of Java. You need to uninstall it via Add/Remove programs and delete the program file also. Then go here Java Update and install the correct version for your system. Choose the offline installation.

    Your running an outdated and unsafe version of Adobe Acrobat Reader latest version. Or get the alternative faster lighter on resources Foxit PDF Reader and Editor Look at the Downloads tab here or Downloads if you don't want to see the features etc.

    After installing. Update Windows also to SP3.

    Your log looks clean. We need to now reset a clean System Restore point. If you don't and you need to use System Restore you will reinfect yourself. Go to Start>Control Panel>System. Click on the System Restore tab and put a check in Turn off System Restore. Then click OK.

    Now go to Start>Help and Support > Undo Changes to Your System or System Restore depending on the make of your PC. Click on what ever will open the System Restore box. You will see two options, Choose Create a System Restore Point. Give it a name like Clean Restore Point and today's date. Now if you need to use it you have it.

    Many infections can be avoided with an added layer of prevention. All recommended programs are free and easy on system resources. You should install them as part of your protection arsenal. Keep MBAM and Spybot Search & Destroy and always immunize SBS&D when you update. You will also need at least one other scanning program Asquared or SuperAntiSpyware are good and there are several other excellent programs with free and paid versions. Read the overviews of what each program below does so you have an understanding of their importance and how to use.

    A firewall and antivirus are also essential. The Windows firewall in XP and Vista is not sufficient.

    Preform Windows Updates monthly on the second Tuesday or use automatic updates, and use your scanners weekly at the least. Always update before you scan.

    Keep other software known for vulnerabilities updated also. Use the Secunia Inspector free scan to identify risks in outdated versions.

    SpywareBlaster from Javacool Software

    WinPatrol by BillPStudios

    SiteHound by FireTrust

    RogueRemover

    hpHosts

    The windows firewall is not sufficient to protect. It doesn't monitor outgoing traffic and this is a must. I use and recommend Online Armor Free

    Also the full protection of MBAM is offered at a very low price, from the link in my signature.

    Update MBAM again, run a quick scan post that and a new HJT log too.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.