Jump to content

Beenthere

Honorary Members
  • Posts

    118
  • Joined

  • Last visited

Posts posted by Beenthere

  1. system volume information stores files from the system restore.

    any files there are harmless UNLESS you use the system restore function to revert your computer back to a certain time.

    the system volume information folder can be easily purged with turning off and turning on the system restore however i wouldn't advise doing this since malwarebytes got rid of that file so it probably wont show up in the next scan

    also, if you turn off and turn on the system restore, you will lose all restore points meaning if something suddenly happens with your computer you cant revert it to a previous state

    As for is it a FP or not, I'm not sure that even experts can tell you because:

    It takes few uncommon steps to get access to that folder(system volume information) and you can easily mess up your comp

  2. Hi,

    I cannot access www.besttechie.net

    I'm lost and I will list out what I have tried so far:

    1. Checked the router settings, everything is fine there

    2. Tried clearing the cache, still can't access

    3. Thought the problem is with my ISP but I asked another guy who has the same ISP as me, he could access the site

    4. When I ping besttechie.net all packets are recieved

    5. Here's the tracert log

    6. Tried both Internet Explorer and Mozilla Firefox

    7. When I put in the IP instead of the name of the site, I get this And when I click on any link, it doesn't work

    8. I thought it might be something in the hosts file. So I opened it and found no traces of besttechie there. I also "disabled" the HOSTS file (I use both mvphosts and spybot's immunize function) but to no avail

    9. With using a proxy site (www.hidemyass.com) I can access the web site

    10. I'm 99% sure I'm clean of malware

  3. I'm browsing this forum i always do (gaming) and on one page my avira popped up saying there is a virus in the cache...

    With my "uber elite" skills, i managed to find out that the file in the cache which avira finds infected is a picture that one guy posted.

    This one

    hxxp://www.homee.com/pic/thread%20sucks.jpg

    I opened the jpg with notepad and found a java script in it that leads to one page that seems legit

    <IFRAME SRC="hxxp://www.ciudad.com.ar/ar/popunder/p_submit.asp?site=personales.ciudad.com.ar" width=1 height=1></IFRAME><script LANGUAGE="JavaScript">//<!--for (var i=1; i<15; i++){  setTimeout('self.focus();',i*30);}//--></SCRIPT><!-- FIN - PUBLICIDAD POP-UP UNDER -->

    What can you tell me about this?

    I dont suppose my PC is infected now -,-

  4. Hi

    I noticed, if I haven't updated mbam for 1 month, the size of the next update will be 2-3 megabytes... If I haven't updated mbam in 1 day, the size of the next update will be 2 megabytes... I don't see the logic in this... cant you guys make the updates smaller? o_o

    I mean the daily updates...

    As for, if a user didn't update for 1 month, you can make that 10 megabytes +

  5. Hello,

    I'm using malwarebytes for more than a year now and every scan would come up clean or sometimes with some false positives. However with today's scan it picked up:

    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\bfast.com (Adware.BHO) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\commission-junction.com (Adware.BHO) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.com (Adware.BHO) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\fastclick.net (Adware.BHO) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\kqzyfj.com (Adware.BHO) -> Quarantined and deleted successfully.HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\P3P\History\linksynergy.com (Adware.BHO) -> Quarantined and deleted successfully.

    I was curious and went to check this part of the registry and there were 100+ keys with names of many sites. Is this the part of the registry where Internet's explorer history is saved? Will it be OK if I delete all these keys here? I guess it will delete the history of Internet Explorer... but since it is a guess I'd need someone to confirm :huh:

    Hmm when I took a better look at the keys, all of the names are some sites I've never visited O_O

    odd

  6. Blah I hate double posting (now remembered the rule you had here about editing)...

    anyways

    the folder didn't got deleted but it's no longer a hidden system file... and there is no autorun.inf in the quarantine.

  7. I became a fan!

    However, I am really wary of Facebook right now ever since I found out about the Worm.Koobface yesterday and since I got re-directed to a nasty site when I tried to log in there (this happened with myspace too). the site was antimalwarescanner . com. I assume that FB had nothing to do with it but since there are so many users on the site it is a prime target for malicious activity, it seems :/

    ?

    This never happened to me and I'm on facebook for months...

    You tried to login on facebook and it redirected you to some nasty site? If that's what you were saying..

    Almost impossible if you aren't infected...

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.