1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

Solved Many Functions Going Haywire.

Discussion in 'Malware and Virus Removal Archive' started by dispatch trophy, 2012/07/24.

  1. 2012/07/26
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    If someone orders online giving credit card numbers, would they have to be changed?
     
  2. 2012/07/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Well it's hard to say. I'd definitely watch your card statements for couple of months. It may be a good idea to call credit card company and make them aware of the issue.

    OTL had some problem with resetting restore point so you'll have to do it manually.
    Turn system restore off.
    Restart computer.
    Turn system restore on.
     

  3. to hide this advert.

  4. 2012/07/26
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    I have set it manually. Malfunction of the restore point was one of the problems and red flags for me from the beginning. It seems like disabling Restore Point is one of the virus's/trojan's functions.

    So if OTL could not make a restore point, doesn't it mean that the virus or whatever it was is still infecting my computer?
     
  5. 2012/07/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    No.
    I've see OTL failing to reset restore points.

    Any other issues?
     
  6. 2012/07/26
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    None so far.

    I will consider the issue resolved.

    Thank you Broni for your help.

    In the "thread tools" drop down menu, there is no option anymore to mark this thread as "resolved." Is that a glitch or continuing action of the trojan?
     
    Last edited: 2012/07/26
  7. 2012/07/26
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Only I can mark this as resolved.

    Good luck and stay safe :)
     
  8. 2012/07/27
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    false alarm.
     
    Last edited: 2012/07/27
  9. 2012/07/28
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    Another trojan was just found on my desktop. It would be nice to know how and why they are the getting in. This is surprising considering the completely that was just completed 2 days ago.

    I think I should get a real time scan from avast or malwarebytes or both to catch them as soon as they enter.

    Here is the malwarebytes scan report:

    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.07.24.02

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 6.0.2900.5512
    user account :: VALUED-7B9600FA [administrator]

    7/28/2012 5:30:53 PM
    mbam-log-2012-07-28 (17-30-53).txt

    Scan type: Full scan (C:\|D:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
    Scan options disabled:
    Objects scanned: 248703
    Time elapsed: 2 hour(s), 24 minute(s), 12 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 1
    C:\Documents and Settings\user account\Local Settings\temp\.exe (Trojan.Agent) -> Quarantined and deleted successfully.

    (end)
     
  10. 2012/07/28
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Run MBAM full scan.
     
  11. 2012/07/29
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    Malwarebytes Anti-Malware 1.62.0.1300
    www.malwarebytes.org

    Database version: v2012.07.29.03

    Windows XP Service Pack 3 x86 NTFS
    Internet Explorer 6.0.2900.5512
    user account :: VALUED-7B9600FA [administrator]

    7/29/2012 2:04:41 AM
    mbam-log-2012-07-29 (02-04-41).txt

    Scan type: Full scan (C:\|D:\|)
    Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P
    Scan options disabled:
    Objects scanned: 250101
    Time elapsed: 2 hour(s), 29 minute(s), 32 second(s)

    Memory Processes Detected: 0
    (No malicious items detected)

    Memory Modules Detected: 0
    (No malicious items detected)

    Registry Keys Detected: 0
    (No malicious items detected)

    Registry Values Detected: 0
    (No malicious items detected)

    Registry Data Items Detected: 0
    (No malicious items detected)

    Folders Detected: 0
    (No malicious items detected)

    Files Detected: 0
    (No malicious items detected)

    (end)
     
  12. 2012/07/29
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You should be good to go :)
     
  13. 2012/08/09
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    I installed Secunia, but that next day many strange things started happening.

    I would try to open Opera browser but Chrome would open, or I would try to open a browser and a text file would open.

    I then uninstalled Secunia, and these problems ceased.
     
  14. 2012/08/09
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Oh well, Secunia is optional so you're fine.
     
  15. 2012/08/10
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    Avast is finding the same trojan:

    Win32:patched-AJD [Trj]

    It is finding it in

    C:\Program Files\Arcsoft\Photostudio5.5\Prine17a.rra

    I did a boot scan again and the trojan came up and it was deleted.

    I had uninstalled and reinstalled my scanner software. Arcsoft is part of that suite.

    At the same time, my color scanner is not working, although the black and white scanning is fine.

    It would be good to know if Win32:patched-AJD really is a trojan and whether that is what is affecting my color scanner.

    I do not understand how a trojan can infect a software cd.
     
  16. 2012/08/10
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
  17. 2012/08/11
    dispatch trophy Contributing Member

    dispatch trophy Inactive Thread Starter

    Joined:
    2011/09/30
    Messages:
    402
    Likes Received:
    0
    I put "Win32:patched-AJD" into the search box of the VirusTotal. No flags came up.

    I am going to see if I can save my color scanner by uninstalling and reinstalling the software and allowing the file.
     
  18. 2012/08/11
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    You can put that file in Avast exceptions.
    I'd also report it at Avast forum.
    They're pretty good with responding.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.