1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Browsers crashing - suspect virus

Discussion in 'Malware and Virus Removal Archive' started by ewanko08, 2011/12/14.

  1. 2011/12/15
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    Now, MBAM did not find any threats. Looks like its clean. I'm currently running Avira AntiVirus now just to be sure. Thanks
     
  2. 2011/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Let me know if anything comes up from that scan or if any other issue arises.
     

  3. to hide this advert.

  4. 2011/12/15
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    Avira reported another Malware. Here's the info:

    Malware Found

    A Virus or unwanted program 'TR/Trash.Gen' was found in file 'C:\System Volume Information\...\A0000028.exe'.

    Access to this file was denied.
     
  5. 2011/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's in one of your restore points.
    It's not active.

    You need to reset your system restore.
    Turn system restore off.
    Restart computer.
    Turn system restore back on.
    How to: Windows XP: http://support.microsoft.com/kb/310405
     
  6. 2011/12/15
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    Is it supposed to delete all restore points? I did that, and then I did a disk cleanup. It says in the report that there are still some obsolete restore points in the system that I can delete. When I try to delete those, Avira reports the same thing "Malware found ".
     
  7. 2011/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    My way of through "disk cleanup "?
     
  8. 2011/12/15
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    I turned off system restore and restarted the computer. Then, I thought I should do a disk cleanup cause I am really running low on disk space. It's around 500mb/15gb right now. And disk cleanup shows that I still have restore points. When I try to delete those, Avira reports the same detection "Malware found ", in system volume information.
     
  9. 2011/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Turn Avira off (or use safe mode) and see if you can delete that restore point.
     
  10. 2011/12/15
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    That did it. I'll proceed running a full system scan with Avira. Thanks!
     
  11. 2011/12/15
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Cool :)....
     
  12. 2011/12/16
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    OK, last night. I ran MalwareBytes twice, and got no detections during the second one. Also ran Avira twice and no detections on 2nd one.

    I'm having troubles with my free memory though. I was able to get around 900mb of free disk space last night. This morning, it went down to around 250mb. I'm not sure if this is System Restore, but I did not do anything significant in the computer yet but just browse the net.

    So I tried running MalwareBytes again, and it detected 9 malwares and I removed them all. Why does my computer keep getting infected. But everything else seems to be working fine now.
     
  13. 2011/12/16
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    And also, I noticed that the proxy in my mozilla changed on its own. This happened once, before I did any of your suggestions. And another time, after I've performed most or all of the steps you gave me.

    Here's the latest MBAM logs:

    Malwarebytes' Anti-Malware 1.51.2.1300
    www.malwarebytes.org

    Database version: 8380

    Windows 5.1.2600 Service Pack 3
    Internet Explorer 7.0.5730.13

    12/16/2011 12:17:29 PM
    mbam-log-2011-12-16 (12-17-29).txt

    Scan type: Quick scan
    Objects scanned: 185487
    Time elapsed: 7 minute(s), 57 second(s)

    Memory Processes Infected: 0
    Memory Modules Infected: 0
    Registry Keys Infected: 6
    Registry Values Infected: 2
    Registry Data Items Infected: 1
    Folders Infected: 0
    Files Infected: 0

    Memory Processes Infected:
    (No malicious items detected)

    Memory Modules Infected:
    (No malicious items detected)

    Registry Keys Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully.

    Registry Values Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\MenuExt\&Search\(default) (Adware.Hotbar) -> Value: (default) -> Quarantined and deleted successfully.
    HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ProxyServer (PUM.Bad.Proxy) -> Value: ProxyServer -> Quarantined and deleted successfully.

    Registry Data Items Infected:
    HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\StartMenuLogoff (PUM.Hijack.StartMenu) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

    Folders Infected:
    (No malicious items detected)

    Files Infected:
    (No malicious items detected)
     
  14. 2011/12/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You have very tiny hard drive and you'll keep running out of space no matter what you do.

    Run FULL scan with MBAM and see if anything will be found.
     
  15. 2011/12/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    We posted at the same time...
     
  16. 2011/12/16
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    THe last logs I posted was from this morning where it found a couple of malwares. Im running a full scan right now to see if there's any more. It did not find anything on a quick scan.
     
  17. 2011/12/16
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Cool :)
     
  18. 2011/12/16
    ewanko08

    ewanko08 Inactive Thread Starter

    Joined:
    2011/12/14
    Messages:
    20
    Likes Received:
    0
    Full scan is finished and no malwares were found. Im just not sure how the pc got reinfected this morning. Anyway, I'll continue to monitor my computer though. Thanks.
     
  19. 2011/12/17
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You should be good to go.
    Let me know if anything new comes up.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.