malware scans

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bladesofhalo, Nov 10, 2006.

  1. Bladesofhalo

    Bladesofhalo MajorGeek

    havent done a scan in a while, just doing it to play it safe, ill post logs
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Logs look ok to me, one thing I was curious about. Are you familiar with "VstPlugins"?
     
  3. Bladesofhalo

    Bladesofhalo MajorGeek

    It might be reminants from the K-Lite mega Codec pack I installed. Did the logs show it as malware of some sort?
     
  4. Bladesofhalo

    Bladesofhalo MajorGeek

    Bjgarrick, i have a program thats called VirusBurst on my pc, and I googled it and its malware?? Might have been installed as soon as I posted my other logs, since other family members were using the pc after I posted. Here are some fresh logs
     

    Attached Files:

  5. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    No, it was just something I'm not used to seeing so it flagged my attention.
     
  6. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please look in Add/Remove Programs for the following and uninstall them if found:

    VirusBursters 6.2

    Now scan with HijackThis and check the boxes for the following entries:
    ( Make sure ALL browser windows are closed when you click FIX )

    R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)

    O4 - HKLM\..\Run: [VirusBursters] C:\Program Files\VirusBursters\virusbursters.exe /h

    O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing)

    Again, make sure ALL browser windows are closed when you click FIX.

    Now, Please boot into Safe Mode, be sure you have the Viewing of Hidden Files & Folders Enabled per the tutorial. Now, navigate to and DELETE the following if they should remain:

    C:\Program Files\VirusBursters Delete this whole folder if it exist!

    C:\Documents and Settings\HP_Owner\Desktop\VirusBursters.lnk

    Next, run CCleaner to clean up cookies and temp files.

    Final Step...

    Reset Web Settings & Default Security Settings:

    To Reset Web Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK.

    If you do not have an Internet Explorer icon on your Desktop, click Start, Control Panel (for some systems it may be Start, Settings, Control Panel), Internet Options, Programs tab and then click "Reset Web Settings". Now go back to the General tab and set your home page address to something useful like www.majorgeeks.com. Click Apply. Click Delete Cookies, Click Delete Files and select Delete all Offline content too, Click OK. When it finishes Click OK


    To Default Security Settings:
    Right click on your desktop Internet Explorer icon and select Properties. Then click the Security Tab and click Default Level for Internet, Local Intranet, Trusted Sites, and Restricted Sites.

    After you complete the above instructions, reboot and see how things are running. Also attach a fresh HJT log.

    Do you know how VirusBurster got installed?
     
  7. Bladesofhalo

    Bladesofhalo MajorGeek

    Thanks for the help Bjgarrick
    Things seem to be running smoothly now.
    Heres a new Hijack this log
    The online scans didnt find anything, but I didnt save them. Do you want me to redo them?
    Im guessing since I recently installed Avast someone thought a second antivirus scanner would help out, so they downloaded and installed VirusBurst.
    Im not exactly sure, since I was gone for about 2 hours and when I got home there was no one here.
    Appreciate the help tough, thanks.
     

    Attached Files:

  8. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your log looks good, if the online scans didnt find anything it's ok.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds