1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Virus on kids laptop

Discussion in 'Malware and Virus Removal Archive' started by GRAHAM WESTON, 2011/12/21.

  1. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    checkup txt as follows.

    Results of screen317's Security Check version 0.99.24
    Windows Vista Service Pack 2 x86 (UAC is enabled)
    Internet Explorer 7 Out of date!
    ``````````````````````````````
    Antivirus/Firewall Check:

    Microsoft Security Essentials
    WMI entry may not exist for antivirus; attempting automatic update.
    ```````````````````````````````
    Anti-malware/Other Utilities Check:

    MVPS Hosts File
    Malwarebytes' Anti-Malware
    CCleaner
    Java(TM) 6 Update 30
    Java(TM) 6 Update 7
    Out of date Java installed!
    Adobe Flash Player ( 10.3.183.10) Flash Player Out of Date!
    Adobe Reader X (10.1.1)
    Mozilla Firefox (3.6.25) Firefox Out of Date!
    ````````````````````````````````
    Process Check:
    objlist.exe by Laurent

    Microsoft Small Business Business Contact Manager BcmSqlStartupSvc.exe
    ``````````End of Log````````````
     
  2. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Do you mean Google Toolbar Notifier?
     

  3. to hide this advert.

  4. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  5. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    When we start EI, we keep getting the message that "Google Toolbar Broker " has stopped working . When you clear the message, it comes straight back again. The computer is currently at 43 % of the run of the ESET online scanner, when it finishes i will post the log, uninstall Java and update Adobe , as you ask above. Currently ESET has found 3 instances of Win32/Patched.HN trojan.

    By the way, what the hell are you doing working on Xmas day, you should be having a day off. And here I thought i was the only workaholic !!!
     
  6. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    I suggest you uninstall/reinstall Google Toolbar for Internet Explorer
     
  7. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    BTW I have some breaks from family duties so I can tale a peek here :)
     
  8. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    I'll uninstall /reinstall google toolbar after scan, currently at 76 % . Thank you for all your help here, i'll be back in the good books with the kids and missus. Just don't get out of the good books with your family for working today. I'll post scan results when finished.
     
  9. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Eset log as follows.

    C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe Win32/Patched.HN trojan cleaned - quarantined
    C:\Program Files\malwarebytes new 2011\Malwarebytes' Anti-Malware\mbamservice.exe Win32/Patched.HN trojan cleaned - quarantined


    cheers.
     
  10. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni, i've looked for Java(TM) 6 Update 7 in programs, done a search for it, but cannot find it on the system, can only find update 30.
     
  11. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    That's fine.

    Your computer is clean [​IMG]

    1. We need to reset system restore to prevent your computer from being accidentally reinfected by using some old restore point(s). We'll create fresh, clean restore point, using following OTL script:

    Run OTL

    • Under the Custom Scans/Fixes box at the bottom, paste in the following:

    Code:
    :OTL
    :Commands
    [purity]
    [emptytemp]
    [EMPTYFLASH]
    [CLEARALLRESTOREPOINTS]
    [Reboot]
    • Then click the Run Fix button at the top
    • Let the program run unhindered, reboot the PC when it is done
    • Post resulting log.

    2. Now, we'll remove all tools, we used during our cleaning process

    Clean up with OTL:

    • Double-click OTL.exe to start the program.
    • Close all other programs apart from OTL as this step will require a reboot
    • On the OTL main screen, press the CLEANUP button
    • Say Yes to the prompt and then allow the program to reboot your computer.

    If you still have any tools or logs leftover on your computer you can go ahead and delete those off of your computer now.

    3. Make sure, Windows Updates are current.

    4. If any Trojan was listed among your infection(s), make sure, you change all of your on-line important passwords (bank account(s), secured web sites, etc.) immediately!

    5. Download, and install WOT (Web OF Trust): http://www.mywot.com/. It'll warn you (in most cases) about dangerous web sites.

    6. Run Malwarebytes "Quick scan" once in a while to assure safety of your computer.

    7. Run Temporary File Cleaner (TFC) weekly.

    8. Download and install Secunia Personal Software Inspector (PSI): http://secunia.com/vulnerability_scanning/personal/. The Secunia PSI is a FREE security tool designed to detect vulnerable and out-dated programs and plug-ins which expose your PC to attacks. Run it weekly.

    9. (optional) If you want to keep all your programs up to date, download and install FileHippo Update Checker.
    The Update Checker will scan your computer for installed software, check the versions and then send this information to FileHippo.com to see if there are any newer releases.

    10. (Windows XP only) Run defrag at your convenience.

    11. When installing\updating ANY program, make sure you always select "Custom " installation, so you can UN-check any possible "drive-by-install" (foistware), like toolbars etc., which may try to install along with the legitimate program. Do NOT click "Next" button without looking at any given page.

    12. Read How did I get infected?, With steps so it does not happen again!: http://www.bleepingcomputer.com/forums/topic2520.html

    13. Please, let me know, how your computer is doing.
     
  12. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni, i'll run all the above as you say. I have already done a windows update, but i found that Microsoft Security Essentials will still not start. I get the message " % 1 is not a valid Win 32 application " with the error code of 0x800700c1 .
     
  13. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    I have also restarted all the Start Up programs that i disabled via msconfig.
     
  14. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Never use "msconfig" as a startup control.

    As for MSE I suggest you uninstall/reinstall it.
     
  15. 2011/12/25
    GRAHAM WESTON

    GRAHAM WESTON Well-Known Member Thread Starter

    Joined:
    2002/07/30
    Messages:
    371
    Likes Received:
    0
    Broni,
    I've uninstalled and reinstaller MSE, all working fine now.I've scanned with MSE and Malwarebytes, and all looks good. Many thanks for all your help with this , greatly appreciated. Hope you have Merry Xmas, and a Prosperous New Year. Again, Many thanks.
     
  16. 2011/12/25
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Very same to you :)

    Way to go!! [​IMG]
    Good luck and stay safe :)
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.