3 critical objects detected

Discussion in 'Malware Help (A Specialist Will Reply)' started by makem, Sep 19, 2008.

  1. makem

    makem Private E-2

    Adaware says: Win32.Backdoor.Asylum and Win32.GenericWorm
    Kaspersky free scan says: C:\windows\system32\oobe\ispsoftware\btyahoo\broadband - not-a-virus

    I don't have any apparent symptoms. I have done all your prerequisits. and attach the result.

    Could someone take the time to assist before 1st Oct when I go to China or leave it until Dec.

    Thanks
     

    Attached Files:

  2. makem

    makem Private E-2

    The last attachment.
     

    Attached Files:

  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    You are way out of date with your copy of MGtools. I don't now where from or when you downloaded it but it was not recently or it was not from Major Geeks. It does not really matter at this point though since your logs are all clean. You do not have any malware. However you do have a big problem. You have no protection. No antivirus, no realtime antispyware, and you are relying on the inadequate windows firewall for a firewall. The last step of the below final instructions will resolve this. And one other item, you need to uninstall the old Sun Java version and install the current version as requested in step 1 of the READ & RUN ME.

    Now we need to cleanup some items from running ComboFix.

    Copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.


    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significan amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix.
    3. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  4. makem

    makem Private E-2

    I run the antivirus/malare/firewall program Outpost which I had turned off as requested. I don't use Windows Firewall. You say my logs are clean yet Adaware and Kaspersky say different. Can you explain this please?
     
    Last edited by a moderator: Sep 19, 2008
  5. makem

    makem Private E-2

    I thought it would help you answer if I used the latest MGTools which I remeber I had difficulty d/l from your site but I got it this time.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I don't believe that Outpost includes a full antivirus program ..... does it. Is this Outpost Pro?

    Kaspersky did not say you had an infection. It said you had something that is not a virus. They are just pointing it as something that you should be aware of and if you installed it an know what it is (which you probably do) then it is not a problem.

    As far as Ad-Aware is concerned, I cannot fully comment without seeing what they are detecting but they are well known for claiming that cookies and MRUs are critical problems which is totally false. Attach a log from Ad-Aware so we can see what they are reporting. Also note that if it is reporting something in System Restore ( the System Volume Information folder) you just need to toggle System Restore off and then back on to remove.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I just checked you new log and see you have the full security suite! It does include everything! Sorry about that.
     
  8. makem

    makem Private E-2

    here do we go from here? Am I infected?
     
  9. makem

    makem Private E-2

    My original post said:

    Adaware says: Win32.Backdoor.Asylum and Win32.GenericWorm

    However I will now do another system scan and post a log.

    Kaspersky warned about mIRC programs I had installed and also this:

    C:\windows\system32\oobe\ispsoftware\btyahoo\broadband - not-a-virus

    I don't use BT as an ISP and also don't use Yahoo that is why I was concerned about that entry.
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes I know but names of infections are not always tha useful. Exactly what and where is more useful which is why a log is better. ;)

    But is is not an infection and you can simply delete the broadband file or ispsoftware folder if you don't use this software from yahoo. Did some one at some point in time use BT or install their software?
     
  11. makem

    makem Private E-2

    No, I installed this OS and I am the only person using this laptop.

    The reg entries you gave have been merged sucessfully.

    Adaware is doing it's stuff and so far reports 4 new critical objects. This is Adaware SE Pro btw.
     
  12. makem

    makem Private E-2

    I have attached the lastest Ad-Aware log. I notice that the 2 objects I initially mentioned are no longer reported.
     

    Attached Files:

  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes and the only thing they are reporting is cookies which are not problems.

    You should be much more concerned with the below which is a potential security risk
    Code:
    "C:\Program Files\"
    FLASHF~1.CRA  15 Aug 2008              "FlashFXP.v3.4.1.1179.WinALL.Cracked-LOVE"
     
  14. makem

    makem Private E-2

    Ok, I will remove that program.

    Many thanks for your prompt and helpful advice.
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Make sure you complete my final steps given in message #3.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds