PDA

View Full Version : comp.virus/bug


speck-chaser
07-12-2010, 08:21 AM
I think my comp might be infected with some type of bug. It works fine for a while ,then will just slow down to a crawl for while. I get pop ups now that I used to not get. I have my msn popup blocker on high. Ive run several scans on my Macafee and it doesnt pick up anything. Anything else to try before bringing it somehere?

longsidelandry
07-12-2010, 08:27 AM
Download Malwarebytes and Spybot Search & Destroy, run those programs.

speck-chaser
07-12-2010, 08:56 AM
mayware,or malware?

longsidelandry
07-12-2010, 09:01 AM
Sorry, Malwarebytes

Yer_Corks_Under
07-12-2010, 09:15 AM
If you do malwarebytes make sure you go to .ORG the other will infect you. www.malwarebytes.org (http://www.malwarebytes.org) this is even better and also free www.superantispyware.com (http://www.superantispyware.com)

tcglsu
07-12-2010, 11:21 AM
I had the same prob the other day I tried all them...didn't work.so I saved all my stuff to my external hard drive and restored it to factory.now it's all good

davethefish1
07-12-2010, 01:36 PM
I think my comp might be infected with some type of bug. It works fine for a while ,then will just slow down to a crawl for while. I get pop ups now that I used to not get. I have my msn popup blocker on high. Ive run several scans on my Macafee and it doesnt pick up anything. Anything else to try before bringing it somehere? First thing I would do is get rid of McSucky(McAffee) worst security on the planet.IMHO (In My Honest Opinion)
Essential Free Security Tools List
ALL OF THESE PROGRAMS ARE FREE!


IF STARTING A THREAD CONCERNING POSSIBLE MALWARE / INFECTIONS PLEASE READ THE FOLLOWING LINK FIRST!!!!!!!!


Computer infected? Commit to Stick with the Clean up until the Computer is Clean. - WorldStart Message Boards


WANT TO KNOW WHAT MALWARE IS

http://www.microsoft.com/security/po.../Glossary.aspx (http://www.microsoft.com/security/portal/Threat/Encyclopedia/Glossary.aspx)


http://www.sophos.com/sophos/docs/eng/sophos-a-to-z.pdf .PDF DOWNLOAD (Need Foxit or Adobe type program to open)


TIPS FOR KEEPING YOUR MACHINE CLEAN OF MALWARE

http://www.mcafee.com/us/threat_center/tips.html


ONLY HAVE ONE OF THESE ANTIVIRUS' INSTALLED AND RUNNING (FOLLOW DIRECTIONS BELOW FOR INSTALLATION)

http://www.avast.com/free-antivirus-download AVAST AV

Manual update link for Avast http://www.avast.com/eng/updates.html

CRITICAL SETTINGS FOR AVAST Antivirus

http://www.filefront.com/15385509/New-Folder.zip/ New settings for Avast version 5.


http://www.avast.com/uninstall-utility

http://www.free-av.com/ AVIRA Antivirus (Windows 2000/XP,Vista/W7)

Manual update link for Avira http://www.avira.com/en/support/vdf_update.html

CRITICAL SETTINGS FOR AVIRA Antivirus


http://www.filefront.com/15924909/Av...20Settings.zip (http://www.filefront.com/15924909/Avira%2010%20Critical%20Settings.zip)


ANTIVIRUS UNINSTALL AND INSTALLATION DIRECTIONS

Download the new AV,disconnect from the internet,uninstall the old AV, reboot the computer,do a search for leftover files and folders from the old AV, deleting them if any are found. Install the new AV,reboot the computer, reconnect to the internet and look for updates.

COMPREHENSIVE LIST OF AV REMOVAL TOOLS (McAfee,Avg.Avira,CA,etc)
http://www.raymond.cc/blog/archives/...irus-software/ (http://www.raymond.cc/blog/archives/2009/05/05/comprehensive-list-of-uninstallers-or-removal-tools-for-antivirus-software/)

NORTON REMOVAL TOOLS

http://service1.symantec.com/Support...05033108162039 (http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039)



ONLY HAVE ONE OF THE FIREWALLS INSTALLED AND RUNNING (DISABLE WINDOWS FIREWALL IF YOU INSTALL ONE OF THESE)

http://www.tallemu.com/downloads.html ONLINE ARMOR Firewall (Windows XP/Vista)
http://download.cnet.com/Online-Armo...-10426782.html

http://forum.worldstart.com/attachme...3&d=1242768312 (http://forum.worldstart.com/attachment.php?attachmentid=47613&d=1242768312) Screen shots for using Online Armor

http://forum.worldstart.com/attachme...2&d=1242768286 (http://forum.worldstart.com/attachment.php?attachmentid=47612&d=1242768286)

http://www.download.com/Comodo-Firew...html?tag=mncol (http://www.download.com/Comodo-Firewall-Pro/3000-10435_4-10460704.html?tag=mncol) COMODO Firewall (Windows XP/Vista)

http://free.agnitum.com/ Outpost Firewall

http://www.pctools.com/firewall/ PC TOOLS FIREWALL


ANTI MALWARE TOOLKIT
http://www.lunarsoft.net/news/lunars...toolkit-113326 (http://www.lunarsoft.net/news/lunarsoft/547-anti-malware-toolkit-113326)

ANTI ROOTKIT TOOL

http://www.gmer.net/#start

ANTISPYWARE/MALWARE SCANNING APPS

http://download.cnet.com/Malwarebyte...=dl&tag=button MALWAREBYTES Updates and scans are manual only in the free version.

Manual update link for Malwarebytes http://mbam.malwarebytes.org/database/mbam-rules.exe


http://www.superantispyware.com/download.html SUPERANTISPYWARE Updates and scans are manual only in free version.



http://www.safer-networking.org/en/download/ SPYBOT S & D Antispyware/malware, immunizer. Don't use the Tea Timer function

http://forum.worldstart.com/attachme...9&d=1246227492 (http://forum.worldstart.com/attachment.php?attachmentid=48109&d=1246227492) Screen shot for disabling Tea Timer function.

ANTIMALWARE/SPYWARE BLOCKER

http://download.cnet.com/SpywareBlas...-10196637.html SPYWAREBLASTER Silently blocks malware,etc.Update it, enable protection for latest updates, close it out. MUST HAVE PROGRAM

http://forum.worldstart.com/attachme...7&d=1237785966 (http://forum.worldstart.com/attachment.php?attachmentid=46807&d=1237785966) Using the program


HIJACK THIS Shows whats running and items can be removed with this

http://free.antivirus.com/hijackthis/

http://forum.worldstart.com/attachme...2&d=1271870068 (http://forum.worldstart.com/attachment.php?attachmentid=50962&d=1271870068)

FILE SCANNER,SUBMIT YOUR FILE TO BE SCANNED BY 20 or MORE SCANNERS
http://virusscan.jotti.org/en


ONLINE SCANNERS One scanner doesn't work properly,pick another one to try. Disable your own Antivirus first to run these

http://www.f-secure.com/en_EMEA/secu...nline-scanner/ (http://www.f-secure.com/en_EMEA/security/security-lab/tools-and-services/online-scanner/)

http://onecare.live.com/site/en-us/default.htm Scan only with IE for this one(Can use Firefox with IE tab addon)

http://www.eset.com/onlinescan/ Scan with IE only for this one (Can use Firefox with IE tab addon)

http://housecall.trendmicro.com/ Scan with IE or Firefox for this one

http://www.bitdefender.com/scanner/o...=scan8/ie.html (http://www.bitdefender.com/scanner/online/free.html?url=scan8/ie.html) Scan with IE only for this one

MICROSOFT MALICIOUS SOFTWARE REMOVAL TOOL

http://www.microsoft.com/security/ma...e/default.aspx (http://www.microsoft.com/security/malwareremove/default.aspx)

RKILL (Stop running malware processes to allow removal) Same tool,different extensions,1 gets blocked by the malware or doesnt work try one of the others

http://download.bleepingcomputer.com/grinler/rkill.com

http://download.bleepingcomputer.com/grinler/rkill.scr SMALL DOS WINDOW (black) APPEARS FOR A FEW SECONDS ONLY

http://download.bleepingcomputer.com/grinler/rkill.exe


WANT TO GET STARTED CLEANING YOUR MACHINE,FOLLOW THESE DIRECTIONS THEN START A THREAD AND POST ALL 3 LOGS

Note: for some infections, Rkill needs to be run first for Malwarebytes to work.

Please download Malwarebytes' Anti-Malware (MBA-M) to your Desktop.
http://www.download.com/Malwarebytes...dlPid=10997763 (http://www.download.com/Malwarebytes-Anti-Malware/3000-8022_4-10804572.html?cdlPid=10997763)

* DoubleClick mbam-setup.exe and follow the prompts to install MBA-M.
* Be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
* If an update is found, it will download and install the latest version if one is available. There are always new updates to the definitions.
* Once the program has loaded, select Perform full scan, then choose the drive(s) then click Scan.
* When the scan is complete, click OK, then Show Results to view the results.
* Be sure that everything is checked, and click Remove Selected if malware is found.
* When MBA-M finishes, Notepad will open with the log. Please save it where you can find it easily.The log can be retrieved by opening up MBAM and clicking on the Logs Tab at the top of the program .

Reboot the computer

Next do this:

Please Run the ESET Online Scanner

http://www.eset.com/onlinescan/scanner.php?i_agree=14
* You will need to use Internet Explorer to to complete this scan and you will need to allow an Active X to be installed or you may use Firefox if you have the IE tab add on.
* You will need to temporarily Disable your current Anti-virus program.
* Be sure the option to Remove found threats is checked and the option to Scan unwanted applications is Checked.
* When you have completed that scan, a scanlog ought to have been created and located at C:\Program Files\EsetOnlineScanner\log.txt.


(One note,if the Eset scan finds malware,choose a few of the online scanners to run from above and run them before posting the HJT log but add those logs to your post also)



Reboot the computer.

Once rebooted right click on the desktop. Choose New Folder name it HiJackThis Folder.
Then download HiJackThis to that HJT folder.
http://download.cnet.com/Trend-Micro...-10227353.html
Do a full system scan with HJT and save the log.


IS YOUR SYSTEM SECURE? SHIELDS UP
https://www.grc.com/x/ne.dll?bh0bkyd2


TEST YOUR DEFENSES HERE

http://www.misec.net/trojansimulator/

FASTONE SCREEN CAPTURE

http://www.afterdawn.com/software/de...pture.cfm/v5_3 (http://www.afterdawn.com/software/desktop_software/graphics/faststone_capture.cfm/v5_3) FASTONE SCREEN CAPTURE Post screen shots to help diagnose problems Make sure its version 5.3,once at this link, click on download to the right.

UNLOCKER

http://www.download.com/Unlocker/300...-10493998.html (http://www.download.com/Unlocker/3000-2248_4-10493998.html) UNLOCKER Stubborn file or folder that wont delete,install this, right click on the file/folder and choose UNLOCKER then delete

MCAFEE SITE ADVISOR

http://www.siteadvisor.com/

WOT(Web of Trust) WOT Warns you about potential risky websites

http://www.mywot.com/

BLOCK ADS IN FIREFOX

https://addons.mozilla.org/en-US/firefox/addon/1865/


JUNK FILE CLEANERS

http://www.ccleaner.com/download CCLEANER
http://www.techsupportalert.com/vide...e-ccleaner.htm (http://www.techsupportalert.com/video-tutorial-how-to-use-ccleaner.htm) Video tutorial on use of Ccleaner


http://www.atribune.org/ccount/click.php?id=1 ATF CLEANER

http://www.atribune.org/index.php?op...d=25&Itemid=25 (http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25) Directions for use of ATF Cleaner

STARTUP ITEMS WEBSITES

http://www.bleepingcomputer.com/startups/ Need to know more about a particular startup item,check it here

http://www.systemlookup.com/ Need to know more about a particular startup item,check it here

START UP CONTROL PROGRAMS

http://www.winpatrol.com/download.html WINPATROL STARTUP CONTROL
Differences between the paid and free version http://www.winpatrol.com/whyplus.html ( I use the paid version(one time fee) for the info link which describes in detail any file or service you click on) ANYTHING tries to startup it will alert you.



http://www.mlin.net/StartupCPL.shtml MIKE LIN'S STARTUP CONTROL PANEL Manage startups.


DO NOT USE MSCONFIG TO DISABLE STARTUPS

Dealing with Startup Processes - MajorGeeks Support Forums

FOOTNOTE:
Only have 1 Antivirus and 1 Antispyware/malware application that has real time protection running at startup(This would pertain to paid versions of Malwarebytes and Superantispyware from this list)
You can have as many of the Antispyware type programs installed to scan with as long as they dont have real time protection(start with Windows with real time protection enabled) as you like.
Spywareblaster does not run with Windows. Install it, update it regularly, enable all protection, close the progam(its still working).


MORE FREE SECURITY TOOLS (Thanks davethefish1)
http://www.techsupportalert.com/cont...list-world.htm (http://www.techsupportalert.com/content/probably-best-free-security-list-world.htm)

speck-chaser
07-12-2010, 11:42 PM
and the short version is?

Ray
07-12-2010, 11:52 PM
and the short version is?

I was thinking the same thing...:rolleyes:

Suthrngntlmn
07-13-2010, 02:01 PM
I'd have to get a new computer before even reading all that...jeezzz

SULPHITE
07-13-2010, 02:14 PM
got some good stuff in there though...