Infected

Discussion in 'Malware Help (A Specialist Will Reply)' started by davepicc, Dec 2, 2005.

  1. davepicc

    davepicc Private E-2

    Well I'm infected again thanks to certain family members that should keep OFF my computer! Sorry just blowing a little steam. I have Syware Doctor unfortunately it wasn't on when the infection happened. I was able to remove the majority of infections such as Trojan.spambot, Email worm win32ProxB, Trojan dropper small AEK, Trojan fakealert, Sypware no and Spyware sheriff. My question is Lavasoft Adware, Spybot, Microsft spyware, and Spyware Doctor are coming up with no infections after following your spyware removal guide (I've been here before). The computer seems to be stable but I know better. I back up to a external FW drive and also have a ghost image that I save on another computer on a regular basis. Since I use the computer for audio recoridng should I just restore it to a previous image instead of going through Hijack this, etc? I haven't restored my OS before using a ghost image or my external hard drive that's why I ask. Thanks again for all your help chaslang.

    Dave
     
  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    We can just clean your machine up to avoid restoring or reinstalling.

    Please download Spy Sweeper
    • Click the link above to download the program.
    • Install it. Once the program is installed, it will open.
    • It will prompt you to update to the latest definitions, click Yes.
    • Once the definitions are installed, click Options on the left side.
    • Click the Sweep Options tab.
    • Under What to Sweep please put a check next to the following:
      • Sweep Memory
      • Sweep Registry
      • Sweep Cookies
      • Sweep All User Accounts
      • Enable Direct Disk Sweeping
      • Sweep Contents of Compressed Files
      • Sweep for Rootkits
      • Please UNCHECK Do not Sweep System Restore Folder.
    • Click Sweep Now on the left side.
    • Click the Start button.
    • When it's done scanning, click the Next button.
    • Make sure everything has a check next to it, then click the Next button.
    • It will remove all of the items found.
    • Click Session Log in the upper right corner, copy everything in that window.
    • Click the Summary tab and click Finish.
    • Paste the contents of the session log you copied into notepad and save it as spysweeper.txt and attach it to your next post along with a fresh HJT log.
     
  3. davepicc

    davepicc Private E-2

    Re: Infected/HJT log/Spysweeper Log

    Thanks a lot for the help bjgarrick.

    Dave
     

    Attached Files:

  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Download this trial version of Ewido Security Suite

    • First, please download and run CCleaner to clean temp files, cookies, etc; to make the log shorter.
    • Install ewido security suite
    • When installing the program, under "Additonal Options" uncheck..
      • Install background guard
      • Install scan via context menu
    • Launch ewido, there should now be an icon on your desktop, double-click it.
    • You will need to update ewido to the latest definition files:
      • On the left hand side of the main screen click update.
      • Then click on Start Update.
    • The update will start and a progress bar will show the updates being installed.
      (the status bar at the bottom will display "Update successful")
    If you are having problems with the updater, you can use this link to manually update ewido. Ewido Manual Updates

    • Once the updates are installed, exit Ewido.
    • Now print the below instructions or save them locally because I want you to have all browsers closed and also have no connection to the internet (unplug your cable) while doing the below:
    • Click on Scanner
    • Then click Settings
    • Under What to Scan? Select Scan every file
    • Then click OK
    • Click on Complete System Scan and the scan will start.
    • Let the program scan the machine
    • While the scan is in progress you will be prompted to clean files that are infected. Leave the defaults selections (to Remove and backup) and click OK. To save yourself some time, you can select Perform action with all infections and then click OK. With the option to scan every file, a lot of cookies will be removed.
    • Once the scan has completed, there will be a button located on the bottom of the screen named Save report[/size][/color]
    • Click Save report
    • Save the report to your desktop or anyplace you will be able to find it to upload here.
    • Reboot into normal mode and reconnect to the internet.
    Once your machine reboots please attach the report from Ewido along with a fresh HJT log from normal mode.
     
  5. davepicc

    davepicc Private E-2

    Thanks again.

    Dave
     

    Attached Files:

  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add or Remove Programs for the following and Uninstall them if found:

    Spy Sweeper

    Ewido


    NEXT:
    Run CCleaner to clean up cookies and temp files.

    Run full scans with Ad-Aware SE & Spybot S&D and have both programs fix what they find.
    Note: Remember to get all updates before doing the scans.

    After you complete the above, reboot and let me know how things are running.
     
  7. davepicc

    davepicc Private E-2

    Things seem to be running fine Bj- thanks for all the help. I assume all the logs look alright? I'm worried this might interfere with all the midi/audio stuff I have to do this weekend. Thanks again for all your help.

    Dave
     
  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert


MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds