Ya'll wont't believe this

Discussion in 'Malware Help (A Specialist Will Reply)' started by tester36, Dec 23, 2005.

  1. tester36

    tester36 Private First Class

    This morning when I closed my bank site it would freeze the screen, It did it twice, I update and run all my scans every weekend. I keep AVG 7.1, SE Personal, SpyBot S& D, Spy Guard, Spyware Blaster, CCleaner, CleanUp, Zone Alarm. I did the run before you post thread and none of my above scans found any thing but I did a Bit defender and Ewido and Malicious Spy ware tool it found nothing but the two onlines did I will post logs I believe these are coming from restorebut I amnot sure and I wondered ilf you could look at my hjt and recommend anything ?
     

    Attached Files:

  2. tester36

    tester36 Private First Class

    bitdefender scan I hope no go says invalid file I did not do some thing right:eek:
     

    Attached Files:

  3. tester36

    tester36 Private First Class

    Win32.Sober.Y@mm

    I also this afternoon did a a2 scan and it fix a Kodak update. I think my son uses AIM but what about the Sober I can't find that exact virus Chaslang since I live on this site how did I get this if not through restore?
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It's in your email! Empty your Deleted Items folder.

    And who downloaded and installed this: C:\Program Files\DogpileToolbar
     
    Last edited: Dec 23, 2005
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  6. tester36

    tester36 Private First Class

    I thought all of that symantec stuff was off of my computer I only use AVG 7.1 for antivirus and I had uninstalled dogpile. I did clean out my deleted items folder in Outlook, boy that was pretty stupid.
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What Symantec stuff?

    What I was showing you was information that Symantec released about malware that was the same as yours.
     
  8. tester36

    tester36 Private First Class

    I am not aware of anyone on this computer downloading dogpile but now anything is possible my son and some of his friends do alot of research for college papers on here too but I am going to ask. When I was looking at the hjt log I saw some entries 016 that had some scanner stuff which you had me delete before but that must be from the online scans this time:eek: .
    Sorry about that this virus stuff makes me crazy. Just about when I get something figured out something else gets on my computer that's why I read here all the time, old but trying to stay ahead. Is the AIM weather bug or the instant messenger ? I know it is a stupid question but I want to be sure I am doing right. Merry Christmas
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes, online scanners will cause O16 lines to appear. The below two were from previously using Symantec's. You can remove them if desired. If you ever use it again they will just re-download and they probably will be updated versions anyway.

    O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
    O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab

    AIM is AOL's instant messenger. WildTangent and a bunch of other crap like Viewpoint stuff get installed when you install anything from AOL. I'm not sure if WeatherBug comes from them too but it does come from alot of places. We always uninstall this stuff.

    Have you taken all the steps in: How to Protect yourself from malware!

    If so, the only thing left is the aspects of how and who uses the PC and what/where they do and go. Smar surfing! Nothing can 100% protect you from you. Some tools help but you can still override them. If someone shuts down the firewall to get past a problem they are having......well you open for problems. If you kids are young, make their accounts restricted and block downloading and installing without your approval. I see you have ZoneAlarm. If it is the free one, by a real copy of the Pro version and password protect it so they cannot change settings in it. There are many steps you can take, but as I'm pointing out, the biggest part of security begins and ends with the PC user. Make sure you re-read steps 9 and 10 of the How to Protect thread.
     
    Last edited: Dec 24, 2005
  10. tester36

    tester36 Private First Class

    Hi Chaslang,
    I appreciate all your help and teaching. My son is 18 and very responsible about where he goes but he does like to talk on AOL instant messenger can I remove the other stuff and leave the messenger part? I religiously update and run all the scans you recommend and when you change the thread I am right there I can't afford to pay these folks to fix that spyware stuff so I try to stay on top of it that is why when my machine started freezing I jumped right on it . Do I need to leave the Ewido running I read on one of the threads that I don't need it. I removed the other 016 as instructed. Thank you so much and have a Merry Christmas.:)
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome. Since you are not running a MS Antispyware you may want to consider keeping Ewido for now (unless it is causing you problems). I know you have SpywareGuard and have used Spybot, but it may be useful to have Ewido. But remember it was only a 15 day trial and is limited in capabilities after that.

    Merry Christmas!
     
  12. tester36

    tester36 Private First Class

    I had MSantispy and liked it alot but it slowed my system down so that we removed it and I started Spyware Guard but if you think that is what I need I will go back and download it just made me so very slow and my work program is a hog sometimes too so it would shut me down any ideas I will gladly try any thing to remain clean
    steph
     
  13. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Had you tried MS AS without SpywareGuard installed?

    Using SpywareGuard, SpywareBlaster, and Spybot with SDhelper and Immunize is pretty reasonable but not necessarily the best. If you cannot take the impact of MS AS on your system, the only other alternatives are to buy some commercial product like Spy Sweeper, CounterSpy, or Ewido and see how they work. You may find they slow your system down too. The resources required to provide good protection are just something you cannot get around. So programs may use fewer resources but may not provide as much protection. The trick is to find one that is good and that works well in your system.

    Other alternatives in the free area are to try things like (they are in no particular order):

    Arovax Shield
    Advanced Spyware Remover
     
  14. tester36

    tester36 Private First Class

    Yes I had MS AS first, I don't know if maybe some things can be disabled or removed from startup but I am not sure about which ones task manager shows 58 processes . That is where it hits me the hardest when I click on an icon to open.
    steph
     
  15. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Do you still have Ewido loaded and running? Running it at the same time as MS AS can slow things down.
     
  16. tester36

    tester36 Private First Class

    Hey
    MS AS was uninstalled in october when the new protect yourself thread came out. I do have Ewido installed and running right now. They never ran together on this computer up until MSAS was removed I was running
    AVG
    SE Personal
    Spybot S&D
    SPY WARE BLASTER
    Ccleaner
    CleanUp
    DM lite 10
    MSAS


    after the middle of november MSAS was removed and Spyware Guard was
    added then on the 23 Dec this thread was started. Just as a note my computer is not running unusually slow at the present time
    steph
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well I guess there is just something about your system that cannot handle MS AS.

    Like any system using XP (especially SP2), the faster the processor and the more memory the better. The demands these days for protection from malware (firewall, AV, AS programs) increase the need for much faster PCs with more memory.
     
  18. tester36

    tester36 Private First Class

    I have decided to try Arovax , I uninstalled ewido with add and remove programs and there is still a file on my desktop ewido-antimalware and it has language defiinitions in it serbian.mo ect ect when I try to delete it it says
    access is denied make sure disk is not full or write protected.:eek:
    steph
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You may still have something from Ewido running (like a service). Post a new HJT log.
     
  20. tester36

    tester36 Private First Class

    hjt log on the way
     

    Attached Files:

  21. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Nothing shows in the log. If you right click on the Desktop icon, what info is there under Properties?

    You can also try renaming the icon. Then reboot into safe mode. Then try to delete it.
     
  22. tester36

    tester36 Private First Class

    it says ewido anti spy malware renamed and deleted thanks
    Steph
     
  23. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome!

    Let me know what you think of Arovax
     
  24. tester36

    tester36 Private First Class

    Hey Chaslang,
    I left the notify me option on until I learn alittle about Arovax and already it has notified me of a test being run on my IE and another intrusion on my e-mail. I am going to leave it that way for a few days I have to go to work but my son is going to watch it and when I check in every day let me know what it says then I think next week I will try the automatic option. So far it is really nice.
    Thanks again many, many times yall are really great no matter what some people write in here!!
    Steph:)
     
  25. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome! And thanks for the feedback on Arovax!
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds