WiredWX Hobby Weather ToolsLog in

 


Security Tool and maybe more malaware

4 posters

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
Ok , I told you I tried Panda Active Scan with Explorer and it doesnt work, doesnt allow it.

Ill do it with Firex Fox brb

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
holy **** I used your Norton removal link, even tho it was the same file I previously used (I think), when I rebooted IE8 final step installation appearred. So Im now scanningonline with IE8 at Panda's! Hooray!

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
Good. I forgot to remove that info in the can about Panda. Panda ActiveScan works on Firefox as well.

Let me know other good details.

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
ouch,

Active Scan is only at 25% and has already found 8 infected files and 1 suspicious.

I hope the free scan fix them and removes them!

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
They are probably all cookies. lol - Very low risk items, if any risk.

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
after like 3 hours scan here's the results. SOme of those look pretty serious

;***********************************************************************************************************************************************************************************
ANALYSIS: 2009-11-15 02:48:38
PROTECTIONS: 0
MALWARE: 17
SUSPECTS: 1
;***********************************************************************************************************************************************************************************
PROTECTIONS
Description Version Active Updated
;===================================================================================================================================================================================
;===================================================================================================================================================================================
MALWARE
Id Description Type Active Severity Disinfectable Disinfected Location
;===================================================================================================================================================================================
00139061 Cookie/Doubleclick TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@doubleclick[1].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@atdmt[3].txt
00139064 Cookie/Atlas DMT TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@atdmt[2].txt
00167753 Cookie/Statcounter TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@statcounter[1].txt
00168110 Cookie/Server.iad.Liveperson TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@server.iad.liveperson[2].txt
00170304 Cookie/WebtrendsLive TrackingCookie No 0 Yes No c:\documents and settings\joe\cookies\joe@statse.webtrendslive[2].txt
00484705 Application/IEDefender HackTools No 0 Yes No c:\documents and settings\joe\bureau\smitfraudfix\iedfix.c.exe
00921467 Generic Malware Virus/Trojan No 0 Yes No c:\documents and settings\joe\bureau\smitfraudfix\404fix.exe
02885963 Rootkit/Booto.C Virus/Worm No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0383015.sys
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1227\a0380090.exe
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0382868.dll
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0382903.dll
03074964 Trj/CI.A Virus/Trojan No 0 Yes No c:\windows\system32\tdlwsp.dll
04753203 Generic Trojan Virus/Trojan No 0 Yes No c:\qoobox\quarantine\c\windows\system32\eventlog.dll.vir
04753203 Generic Trojan Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0383012.dll
05502564 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1227\a0380093.exe
05521696 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1227\a0380094.exe
05532725 Trj/Sinowal.WPD Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0382964.exe
05532725 Trj/Sinowal.WPD Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1225\a0376680.exe
05539275 Trj/Nabload.ACN Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0382953.exe
05539275 Trj/Nabload.ACN Virus/Trojan No 0 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1225\a0376686.exe
05541364 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1227\a0380091.exe
05547123 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\qoobox\quarantine\c\windows\system32\yqrnld50e.dll.vir
05547123 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1230\a0383011.dll
05547123 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1225\a0376685.dll
05561427 Trj/Zlob.KH Virus/Trojan No 1 Yes No c:\system volume information\_restore{2db89fae-fd84-4155-b10a-30faab005922}\rp1227\a0380092.exe
;===================================================================================================================================================================================
SUSPECTS
Sent Location
;===================================================================================================================================================================================
No c:\documents and settings\joe\bureau\smitfraudfix.exe
;===================================================================================================================================================================================
VULNERABILITIES
Id Severity Description
;===================================================================================================================================================================================
;===================================================================================================================================================================================

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
I think the files with digits is Security Tool ready to comeback on first restore.

How can I prevent this?

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
Now to get you off to a good start we will clean your restore points so that all the bad stuff is gone for good. Then if you need to restore at some stage you will be clean. There are several ways to reset your restore points, but this is my method:
  • Select Start > All Programs > Accessories > System tools > System Restore.
  • On the dialogue box that appears select Create a Restore Point
  • Click NEXT
  • Enter a name e.g. Clean
  • Click CREATE

You now have a clean restore point, to get rid of the bad ones:
  • Select Start > All Programs > Accessories > System tools > Disk Cleanup.
  • In the Drop down box that appears select your main drive e.g. C
  • Click OK
  • The System will do some calculation and the display a dialogue box with TABS
  • Select the More Options Tab.
  • At the bottom will be a system restore box with a CLEANUP button click this
  • Accept the Warning and select OK again, the program will close and you are done


==

Download Security Check by screen317 from SpywareInfoforum.org or Changelog.fr.
  • Save it to your Desktop.
  • Double click SecurityCheck.exe and follow the onscreen instructions inside of the black box.
  • A Notepad document should open automatically called checkup.txt; please post the contents of that document.

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
Hi Dragon Mastah Jay

Here's the thinghie:

Results of screen317's Security Check version 0.99.0
Windows XP Service Pack 3
``````````````````````````````
Antivirus/Firewall Check:

Clean Virus MSN
``````````````````````````````
Anti-malware/Other Utilities Check:

Ad-Aware
SUPERAntiSpyware Free Edition
HijackThis 2.0.2
Adobe Flash Player 10
Adobe Reader 7.0.7 - Français
Out of date Adobe Reader installed!
``````````````````````````````
Process Check:
objlist.exe by Laurent

Ad-Aware AAWService.exe is disabled!
Ad-Aware AAWTray.exe is disabled!
``````````````````````````````
DNS Vulnerability Check:

GREAT! (Not vulnerable to DNS cache poisoning)

`````````End of Log```````````

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
Please download the newest version of Adobe Acrobat Reader from Adobe.com

Before installing: it is important to remove older versions of Acrobat Reader since it does not do so automatically and old versions still leave you vulnerable.
Go to the Control Panel and enter Add or Remove Programs.
Search in the list for all previous installed versions of Adobe Acrobat Reader. Uninstall/Remove each of them.

Once old versions are gone, please install the newest version.

==

Please read the following information that I have provided, which will help you prevent malicious software in the future. Please keep in mind, malware is a continuous danger on the Internet. It is highly important to stay safe while browsing, to prevent re-infection.

Software recommendations

Antivirus/Antispyware

  • Microsoft Security Essentials: this is Microsoft's free antivirus/antispyware program. It equips you with protection against viruses, spyware, trojans, rootkits, and worms. It is also light on the computer's performance. Note: when installing this, you have both an antivirus and antispyware. Make sure you also get a firewall.
  • AVG Free: this is one of the most powerful, and easiest to use security software. The free version equips you with protection against viruses, spyware, trojans, rootkits, worms, and rogue software. Note: when installing this, you have both an antivirus and antispyware. Make sure you also get a firewall.


Firewall

  • Tallemu Online Armor: the free version is just as good as the premium. I have linked you to the free version.
  • Comodo Firewall: the free version is just as good as the premium. I have linked you to the free version. The optional security suite enhances the firewall by 40% increase. If you would like to install the suite that includes antivirus, then remove your old antivirus first.
  • PC Tools Firewall Plus: free and excellent firewall.


Note: Please keep ALL of these programs up-to-date and run them whenever you suspect a problem to prevent malware problems.

Resident Protection help
A number of programs have resident protection and it is a good idea to run the resident protection of one of each type of program to maintain protection. However, it is important to run only one resident program of each type since they can conflict and become less effective. That means only one antivirus, firewall, and scanning anti-spyware program at a time. Passive protectors such as SpywareBlaster can be run with any of them.

Rogue programs help
There are a lot of rogue programs out there that want to scare you into giving them your money and some malware actually claims to be security programs. If you get a popup for a security program that you did not install yourself, do NOT click on it and ask for help immediately. It is very important to run an antivirus and firewall, but you can't always rely on reviews and ads for information. Ask in a security forum that you trust if you are not sure. If you are unsure and looking for anti-spyware programs, you can find out if it is a rogue here:
http://www.spywarewarrior.com/rogue_anti-spyware.htm

Securing your computer

  • Windows Updates - It is very important to make sure that both Internet Explorer and Windows are kept current with the latest critical security patches from Microsoft. To do this just start Internet Explorer and select Tools > Windows Update, and follow the online instructions from there.
  • hpHosts file replaces your current HOSTS file with one containing well known ad sites and other bad sites. This prevents your computer from connecting to those sites by redirecting them to 127.0.0.1, which is your local computer's loopback address, meaning it will be difficult to infect your computer in the future.


Please consider using an alternate browser
Mozilla's Firefox browser is a very good alternative. In addition to being generally more secure than Internet Explorer, it has a very good built-in popup blocker and add-ons, like NoScript, can make it even more secure. Opera is another good option.

If you are interested:

  • Firefox may be downloaded from here: http://www.getfirefox.com
  • Opera is available here: http://www.opera.com/download/


Thank you for choosing GeekPolice. Please see this page if you would like to leave feedback or contribute to our site. Do you have any more questions?

descriptionSecurity Tool and maybe more malaware - Page 7 EmptyRe: Security Tool and maybe more malaware

more_horiz
privacy_tip Permissions in this forum:
You cannot reply to topics in this forum