MajorGeeks Support Forums

Go Back   MajorGeeks Support Forums > ----------= PC, Desktop and Laptop Support =---------- > Malware Removal
Register FAQ Members List Calendar Casino Mark Forums Read

Malware Removal Malware removal forum. Please see the READ ME FIRST thread before you post. Forum is staffed by a small number of volunteers, please be patient.


Reply
 
Thread Tools Display Modes
  #1  
Old 11-12-08, 09:47
KiLL CraZy KiLL CraZy is offline
Private First Class
 
Join Date: Mar 2007
Posts: 67
Thanks: 2
Thanked 0 Times in 0 Posts
Default SBS_VE_AMBR_2008101... viruse/malware?

so for about a few weeks now. every night, my counterspy would be scheduled to run over night and then next morning when I wake up, my symantec antivirus auto protect would be on screen waiting for me to see its results which I included in a picture below.

So i would remove it and etc etc and then the next morning, once again it will pop up after a counterspy scan, this happened for a while already so last week I did the malware removal guide to see if it fixed it, the scans didn't really detect nothing serious from what I saw.

But then still the next morning, once again, I would see my auto protect box up with threats in them, my computer hasn't been slowing down or anything, in all honesty i haven't seen anything diff, my pc runs normal with no problems, occasionally it would freeze up but other then that everything is fine.

ANyone have a clue on what these things r thats my antivirus is detecting?
Attached Images
File Type: jpg untitled.JPG (80.6 KB, 8 views)
Reply With Quote
Sponsored links
  #2  
Old 11-12-08, 11:16
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,098
Thanks: 991
Thanked 3,783 Times in 3,684 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

Welcome to Major Geeks!

Please follow the instructions in the below link and attach the requested logs when you finish these instructions.
  • If something does not run, write down the info to explain to us later but keep on going.
  • Do not assume that because one step does not work that they all will not.
READ & RUN ME FIRST. Malware Removal Guide

Notes:
  1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, You can try running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
  2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.


Plus a guide on HOW TO: Attach Items To Your Post
Reply With Quote
  #3  
Old 11-12-08, 14:13
KiLL CraZy KiLL CraZy is offline
Private First Class
 
Join Date: Mar 2007
Posts: 67
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

thanks for the reply kertrel, here are my logs
Attached Files
File Type: log SASlog.log (465 Bytes, 5 views)
File Type: txt Malwarebytes ANti-log.txt (832 Bytes, 4 views)
File Type: txt ComboFix.txt (14.2 KB, 4 views)
Reply With Quote
  #4  
Old 11-12-08, 14:14
KiLL CraZy KiLL CraZy is offline
Private First Class
 
Join Date: Mar 2007
Posts: 67
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

last one

how's it looking?

through all the scans nothing came up bad, all of the scans passed.

But I guarantee if I do a full system scan with counterspy/ or antivirus, once it is complete, it will come up with those SBS stuff again...
Attached Files
File Type: zip MGlogs.zip (58.9 KB, 5 views)
Reply With Quote
  #5  
Old 11-12-08, 16:09
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,098
Thanks: 991
Thanked 3,783 Times in 3,684 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

Please be patient while I take a look thru your logs.
Thanks
Kes
Reply With Quote
Sponsored links
  #6  
Old 11-12-08, 18:28
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,098
Thanks: 991
Thanked 3,783 Times in 3,684 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

Hi

I am not seeing any malware in your logs. What you have Symantec reporting is more than likely a false positive.

1) Please run the below:

Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
  • Double-click ATF-Cleaner.exe to run the program.
  • Under Main choose: Select All
  • Click the Empty Selected button.

If you use Firefox browser
  • Click Firefox at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

If you use Opera browser
  • Click Opera at the top and choose: Select All
  • Click the Empty Selected button.
  • NOTE: If you would like to keep your saved passwords, please click No at the prompt.

Click Exit on the Main ATF Cleaner menu to close the program.


2) If you are not having any other malware problems, it is time to do our final steps:
  1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
  2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
    • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
    • "%userprofile%\Desktop\combofix" /u
      • Notes: The space between the combofix" and the /u, it must be there.
      • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    • Delete the C:\combofix folder from combofix (if it exists)
  3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
  4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
  5. Go to add/remove programs and uninstall HijackThis.
  6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
  7. If you are running Vista, Windows XP or Windows ME, do the below:
    • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
    • Then reboot and Enable System Restore to create a new clean Restore Point.
  8. After doing the above, you should work thru the below link:

Last edited by Kestrel13!; 11-12-08 at 18:36..
Reply With Quote
The Following User Says Thank You to Kestrel13! For This Useful Post:
KiLL CraZy (11-12-08)
  #7  
Old 11-12-08, 23:56
KiLL CraZy KiLL CraZy is offline
Private First Class
 
Join Date: Mar 2007
Posts: 67
Thanks: 2
Thanked 0 Times in 0 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

thanks you for your help kestler, did all your steps and i guess ill just wait to see if Symantec reports those false stuff again.

Quick question, currently I use counterspy and symantec antivirus on my pc to protect against virus, etc... are those 2 good to have or do you have any recomendation on any software thats better then these two?

Once again, I greatly appreciate your help and thank you so much!
Reply With Quote
  #8  
Old 11-13-08, 12:37
Kestrel13!'s Avatar
Kestrel13! Kestrel13! is offline
Super Malware Fighter - Major Dilemma
 
Join Date: Apr 2007
Location: cloud cuckoo land
Posts: 29,098
Thanks: 991
Thanked 3,783 Times in 3,684 Posts
Default Re: SBS_VE_AMBR_2008101... viruse/malware?

Hi

I personally opt to stay away from the paid for security suites as they tend to bog down the computer. I favour freeware anti-virus and anti spyware apps as I believe they do the job equally as well. I also have MBAM and SAS on all my machines. It's down to user preference and there aren't any right or wrong answers so to speak.

You're welcome for the help.
All the best
Kes
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
PLZ HELP!!!!! TROJANS AND MALWARE TR/Vundo.Gen, TR/Click.HD, HEUR/Malware Female Body Investigator Malware Removal 5 06-24-08 02:06
malware braviax.exe installing malware winreanimator.exe subhuman_bob Malware Removal 1 02-25-08 18:53
Malware problem not fixed with Malware Removal instructions aagarwal584 Malware Removal 9 12-27-07 02:19
Please Please Help- viruse ridden computer COMPUTER STUFFED Malware Removal 1 11-25-06 11:53
help i got viruse and spyware... vanessah Malware Removal 4 12-10-03 18:44


All times are GMT -5. The time now is 17:21.

MajorGeeks.Com Menu

MajorGeeks.Com \ All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ NEW! PC Games \ System Tools \ Macintosh \ Demonews.Com \ Top Downloads

MajorGeeks.Com \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds


All content Copyright MajorGeeks.com source code Powered by vBulletin® Version 3.8.4
Copyright © 2009 vBulletin Solutions, Inc. All rights reserved.
Ad Management by RedTyger