MrCharlie Posted October 31, 2013 ID:748480 Share Posted October 31, 2013 Please run a free online scan with the ESET Online Scanner (it may take a while to run) Note: You will need to use Internet Explorer for this scan. First please Disable any Antivirus you have active, as shown in This Topic Note: Don't forget to re-enable it after the scan. http://www.eset.eu/online-scanner Tick the box next to YES, I accept the Terms of Use. Click Start When asked, allow the ActiveX control to install Click Start Make sure that the options Remove found threats is unchecked and the option Scan unwanted applications is checked Click Advanced settings and select the following:Scan potentially unwanted applicationsScan for potentially unsafe applicationsEnable Anti-Stealth technologyClick Start Wait for the scan to finish If threats were found: Click on "list of threats found" Click on "export to text file" and save it as ESET SCAN and save to the desktop Click on back Put a checkmark in "Uninstall application on close" Click on finish Post back the log.....MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 1, 2013 Author ID:748880 Share Posted November 1, 2013 Eset showed almost 832 threats of sort!ESET SCAN.txt Link to post Share on other sites More sharing options...
MrCharlie Posted November 1, 2013 ID:748884 Share Posted November 1, 2013 That's not good....see if the ESETGoblinCleaner tool works:http://kb.eset.com/esetkb/index?page=content&id=SOLN3157MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 2, 2013 Author ID:749133 Share Posted November 2, 2013 So I've run a number of scans now with esetgoblincleaner and it appears to have cleaned all the files. Should I run the trial version of the software again or something else? Link to post Share on other sites More sharing options...
MrCharlie Posted November 2, 2013 ID:749206 Share Posted November 2, 2013 I would run another scan with ESET now. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 3, 2013 Author ID:749470 Share Posted November 3, 2013 I ran eset Online Scanner again, it again came up with about 350 or so infected files. I ran GoblinCleaner again but it was not able to find any or remove any of the infected files. I've attached the second scan results from ESET.ESET SCAN-2.txt Link to post Share on other sites More sharing options...
MrCharlie Posted November 3, 2013 ID:749547 Share Posted November 3, 2013 This is a nasty virus and I think the best course of actions would be to wipe the drive clean and start over. If we run a different scanner it will most likely just delete or quarantine the files. Let me know what you think. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 3, 2013 Author ID:749637 Share Posted November 3, 2013 What about investing in ESET tools to get a deeper clean? Would that be advised? Since Eset seems to be the one finding the viruses that is? Link to post Share on other sites More sharing options...
MrCharlie Posted November 3, 2013 ID:749652 Share Posted November 3, 2013 You can run ESET, but it's only going to delete/quarantine the files. Give it a try. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 5, 2013 Author ID:750197 Share Posted November 5, 2013 I just wanted to give you a heads up, I'm still in the process of cleaning, quarantining and deleting. Will deleting the file resolve the situation if it has been quarantined but a clean solution is not available or is it going to break some applications? Link to post Share on other sites More sharing options...
MrCharlie Posted November 5, 2013 ID:750218 Share Posted November 5, 2013 Deleting or quarantine is OK, but most likely the app it's associated with won't work and have to be reinstalled. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 7, 2013 Author ID:751020 Share Posted November 7, 2013 I've scanned my directories, it took over 47 hours to complete but now finished, cleaned, quarantined and deleted. I'm running another ESET scan now but that wont complete until Saturday or Sunday I'd imagine, part of my issue is that I have over 30TB of storage although I do not have the scan set to scan the archives or backup directories. What type of scan should I run next? Link to post Share on other sites More sharing options...
MrCharlie Posted November 7, 2013 ID:751030 Share Posted November 7, 2013 ESET should do it. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 7, 2013 Author ID:751036 Share Posted November 7, 2013 You've been extremely helpful in assisting me in resolving this situation. I'm glad it has not required a complete reinstall of the OS, that is always a most painful experience and typically takes me a week or so to get it running right again and months back to where it would have been. I will update you again once the scan is complete and I've run Malwarebytes again. Link to post Share on other sites More sharing options...
MrCharlie Posted November 7, 2013 ID:751046 Share Posted November 7, 2013 OK...when you're ready............ Lets check your computers security before you go and we have a little cleanup to do also: Download Security Check by screen317 from HERE or HERE.Save it to your Desktop.Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.If you get Unsupported operating system. Aborting now, just reboot and try again.A Notepad document should open automatically called checkup.txt.Please Post the contents of that document.Do Not Attach It!!!MrC Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted November 12, 2013 Root Admin ID:752534 Share Posted November 12, 2013 Are you still with us? Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 12, 2013 Author ID:752567 Share Posted November 12, 2013 I had to go out of town for a few days. However it invested in Eset and ran a deep clean twice. The first time netted over 2000 infected files, I was able to clean, quarantine and delete 100% of them. I ran a deep clean again and it was completely clean, zero infected files. I then ran MalwareBytes deep clean and found nothing.I've not run the most recent tool you gave me but will run it when I get back. Is there another tool or any log files you'd like me to pull and attach? Link to post Share on other sites More sharing options...
MrCharlie Posted November 12, 2013 ID:752623 Share Posted November 12, 2013 No, just run Security Check. MrC Link to post Share on other sites More sharing options...
JeckylPhoto Posted November 14, 2013 Author ID:753506 Share Posted November 14, 2013 Here is what came back from SecurityCheck.exe: Results of screen317's Security Check version 0.99.76 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 10 ``````````````Antivirus/Firewall Check:`````````````` Windows Firewall Enabled! ESET NOD32 Antivirus 4.2 Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware version 1.75.0.1300 Adobe Flash Player 11.9.900.117 Mozilla Firefox 19.0 Firefox out of Date! ````````Process Check: objlist.exe by Laurent```````` ESET NOD32 Antivirus ekrn.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: 4%````````````````````End of Log`````````````````````` Link to post Share on other sites More sharing options...
MrCharlie Posted November 14, 2013 ID:753580 Share Posted November 14, 2013 Out dated programs on the system are vulnerable to malware.Please update or uninstall them:-----------------------------------------Mozilla Firefox 19.0 Firefox out of Date! <----please check for an update if available. (25)-------------------------------------------A little clean up to do....Please Uninstall ComboFix: (if you used it)Press the Windows logo key + R to bring up the "run box"Copy and paste next command in the field:ComboFix /uninstallMake sure there's a space between Combofix and /Then hit enter.This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point(If that doesn't work.....you can simply rename ComboFix.exe to Uninstall.exe and double click it to complete the uninstall or download and run the uninstaller)---------------------------------Please download OTC to your desktop.http://oldtimer.geekstogo.com/OTC.exeDouble-click OTC to run it. (Vista and up users, please right click on OTC and select "Run as an Administrator")Click on the CleanUp! button and follow the prompts.(If you get a warning from your firewall or other security programs regarding OTC attempting to contact the Internet, please allow the connection.)You will be asked to reboot the machine to finish the Cleanup process, choose Yes.After the reboot all the tools we used should be gone.Note: Some more recently created tools may not yet be removed by OTC. Feel free to manually delete any tools it leaves behind.Any other programs or logs you can manually delete.IE: RogueKiller.exe, RKreport.txt, RK_Quarantine folder, C:\FRST, MBAR, etc....AdwCleaner > just run the program and click uninstall.Note:If you used FRST and can't delete the quarantine folder:Download the fixlist.txt to the same folder as FRST.exe.Run FRST.exe and click Fix only once and waitThat will delete the quarantine folder created by FRST.The rest you can manually delete.-------------------------------Any questions...please post back.If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.Take a look at My Preventive Maintenance to avoid being infected again. (also HERE)Good Luck and Thanks for using the forum, MrC Link to post Share on other sites More sharing options...
Root Admin AdvancedSetup Posted November 15, 2013 Root Admin ID:754136 Share Posted November 15, 2013 Glad we could help. If you need this topic reopened, please send a Private Message to any one of the moderating team members. Please include a link to this thread with your request. This applies only to the originator of this thread. Other members who need assistance please start your own topic in a new thread. Thanks! Link to post Share on other sites More sharing options...
Recommended Posts