1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved bogus AV, redirected URLs, and can't get Windows Updates

Discussion in 'Malware and Virus Removal Archive' started by joshcsmith13, 2010/07/31.

  1. 2010/08/03
    joshcsmith13

    joshcsmith13 Inactive Thread Starter

    Joined:
    2010/07/30
    Messages:
    18
    Likes Received:
    0
    unbelievable.... as if having a virus trash my machine isn't bad enough, we had a terrible thunderstorm here yesterday that blew out my [wireless] router, which is the only internet connection I have for my PC right now. (I'm at work right now.) So, I didn't get any more scanning done last night. hopefully I can get this fixed or replaced soon and get things back on track!
     
  2. 2010/08/03
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Didn't you know, that troubles travel in bunches?.....hehehehe
     

  3. to hide this advert.

  4. 2010/08/04
    joshcsmith13

    joshcsmith13 Inactive Thread Starter

    Joined:
    2010/07/30
    Messages:
    18
    Likes Received:
    0
    don't remind me...
    in the midst of this, we are also down 2 smartphones. I credit my wife with both losing hers and then damaging mine after I was kind enough to loan it to her. :(
     
  5. 2010/08/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Keep me posted :)
     
  6. 2010/08/04
    joshcsmith13

    joshcsmith13 Inactive Thread Starter

    Joined:
    2010/07/30
    Messages:
    18
    Likes Received:
    0
    Security Check log below. TFC ran successfully. Now waiting for Kaspersky to download.... man it's slow.

    Results of screen317's Security Check version 0.99.4
    Windows XP Service Pack 3
    Internet Explorer 8
    ``````````````````````````````
    Antivirus/Firewall Check:

    Windows Firewall Enabled!
    avast! Free Antivirus
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    Malwarebytes' Anti-Malware
    Java(TM) 6 Update 21
    Out of date Java installed!
    Adobe Flash Player
    Adobe Reader 9.3.3
    Mozilla Firefox (3.6.8)
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Alwil Software Avast5 AvastSvc.exe
    ALWILS~1 Avast5 avastUI.exe
    ````````````````````````````````
    DNS Vulnerability Check:

    GREAT! (Not vulnerable to DNS cache poisoning)

    ``````````End of Log````````````
     
  7. 2010/08/04
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I know :)
     
  8. 2010/08/05
    joshcsmith13

    joshcsmith13 Inactive Thread Starter

    Joined:
    2010/07/30
    Messages:
    18
    Likes Received:
    0
    Here's the Kaspersky log. interesting... I've had Unlocker for quite a while and never noticed any problems. I suppose I can get rid of it if I have to.

    --------------------------------------------------------------------------------
    KASPERSKY ONLINE SCANNER 7.0: scan report
    Thursday, August 5, 2010
    Operating system: Microsoft Windows XP Home Edition Service Pack 3 (build 2600)
    Kaspersky Online Scanner version: 7.0.26.13
    Last database update: Wednesday, August 04, 2010 21:30:44
    Records in database: 4149589
    --------------------------------------------------------------------------------

    Scan settings:
    scan using the following database: extended
    Scan archives: yes
    Scan e-mail databases: yes

    Scan area - My Computer:
    C:\
    D:\
    E:\

    Scan statistics:
    Objects scanned: 67275
    Threats found: 1
    Infected objects found: 1
    Suspicious objects found: 0
    Scan duration: 01:34:34


    File name / Threat / Threats count
    C:\Documents and Settings\Josh\My Documents\My Downloads\unlocker1.8.8.exe Infected: not-a-virus:AdWare.Win32.NSIS.a 1

    Selected area has been scanned.
     
  9. 2010/08/05
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We won't worry about it.
    I use Unlocker too.
    Possibly, some new download has some kind of toolbar, or other garbage pre-checked.

    In any case....

    OTL Clean-Up
    Clean up with OTL:

    * Double-click OTL.exe to start the program.
    * Close all other programs apart from OTL as this step will require a reboot
    * On the OTL main screen, press the CLEANUP button
    * Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    ================================================================

    Your computer is clean :)

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point.

    Turn off System Restore:

    - Windows XP:
    1. Click Start.
    2. Right-click the My Computer icon, and then click Properties.
    3. Click the System Restore tab.
    4. Check "Turn off System Restore ".
    5. Click Apply.
    6. When turning off System Restore, the existing restore points will be deleted. Click Yes to do this.
    7. Click OK.
    - Windows Vista and 7:
    1. Click Start.
    2. Right-click the Computer icon, and then click Properties.
    3. Click on System Protection under the Tasks column on the left side
    4. Click on Continue on the "User Account Control" window that pops up
    5. Under the System Protection tab, find Available Disks
    6. Uncheck the box for any drive you wish to disable system restore on (in most cases, drive "C: ")
    7. When turning off System Restore, the existing restore points will be deleted. Click "Turn System Restore Off" on the popup window to do this.
    8. Click OK

    2. Restart computer.

    3. Turn System Restore on.

    4. Make sure, Windows Updates are current.

    [SIZE= "4"]5. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately![/SIZE]

    6. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    7. Run defrag at your convenience.

    8. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    9. Please, let me know, how is your computer doing.
     
  10. 2010/08/07
    joshcsmith13

    joshcsmith13 Inactive Thread Starter

    Joined:
    2010/07/30
    Messages:
    18
    Likes Received:
    0
    All right! everything's looking good. So, like I mentioned earlier, I'm rather disappointed that my antivirus (Avast) didn't catch this thing before it messed me up, but it seems that's kind of typical of antivirus products these days - you have to get some seperate scanner or tool to prevent/protect against malware and spyware. Why is that?? Other than the WOT that you recommended, are there any anti-malware products that you would recommend (especially free!)?

    btw, we (my 3 yr old son) found one of the smarthpones(!) and the other one is going to undergo surgery after I get a screen repair kit, and I've got a new power-supply for the router on its way. :)

    Thanks Again!!
     
  11. 2010/08/07
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Good news :)

    Well, that's how dangerous our computer world is...

    Your AV, a firewall, Malwarebytes run on occasion and you'll be OK.
    Run TFC weekly.

    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.