also @ TechSpot: Qualcomm shows off Mirasol, 1.5-inch panel shipping in products soon

Registry Keys Infected

Discussion in 'Virus and Malware Removal' started by Manjit, Jan 17, 2009.

  1. Manjit Newcomer, in training Posts: 82

    Here are the logs requested 'mflynn'

    I should say it Avast network shield that is giving me protection from 'Dcom Exploit' at the moment. As my firewall is 'Online Amour' and is only free thus only offers limited tools.

    @LookinAround

    I've got a wireless router that I used to use to connect my broadband internet modem to another laptop in the house. Would that router work for the purposes of what we are trying to achieve here?

    Thanks for your helps guys.
  2. mflynn Newcomer, in training Posts: 2,793

    Opps run SAS again as it found some Vundo! We need to confirm it clean!

    Then Start-Run
    type
    combofix /u
    Click OK or hit Enter key

    This uninstalls Combofix.

    Now get new and run it.

    Download ComboFix

    NOTE: If you have had ComboFix more than a few days old delete and re-download.

    Get it here: http://download.bleepingcomputer.com/sUBs/ComboFix.exe
    Or here: http://subs.geekstogo.com/ComboFix.exe

    Double click combofix.exe follow the prompts.

    Install Recovery Console if connected to the Internet!

    When finished, it will open a log.
    Attach the log and a new HJT log in your next reply.

    Note: Do not click combofix's window while its running. That may cause it to stall.

    Mike
  3. Manjit Newcomer, in training Posts: 82

    Here are the logs requested.

    I did a full scan with SAS with TeaTimer in SpyBot turned off and the realtime protection turned off in Windows Defender. In the full scan it did not show any Vundo.

    Manjit
  4. mflynn Newcomer, in training Posts: 2,793

    Wait for LookinAround opinion also.

    But it seems exactly what he was proposing!

    Your logs are now clean.

    Mike
  5. LookinAround TechSpot Chancellor Posts: 7,677   +39

    Yes, that router should work just fine. I'm guessing the wireless router also has LAN ports so it can connect both wireless and wired?

    But now i'm curious.. if the computer in question is not usually connected to the router you mention BUT you do have a router connected to your modem connected to your ISP?... how do you usually connect the computer in question?? As, if in fact, your "broadband modem" allows for more then just one LAN cable.. my guess is it might be able to function as a router itself!
  6. Manjit Newcomer, in training Posts: 82

    @LookinAround

    It's all getting rather confusing lol.

    The best I can explain is that I have a broadband connection which comes from a seperate broadband modem it only allows for one 'LAN connection' (i.e ethernet cable). This is what I am currently using to connect to my laptop.

    A while ago I used a wireless router to connect the broadband modem. This enabled my laptop and my brothers computer to share the internet connection.

    So I guess the best thing to do would to re-set the wireless router just for my laptop, re-installing the software and block tcp/135.

    Or could I adjust the settings with the broadband modem?

    Once again thank you for assitance. Your help is greatly appreciated.
     
  7. LookinAround TechSpot Chancellor Posts: 7,677   +39


    I just re-read your earlier post and see it should be simple. (I didn't notice before you had said it in past tense as in "used to use it" so just my confusion, but now fixed :) '

    So it sounds like it will be connected something like this:

    Code:
    Broadband                           [I]wired (or wireless) connection [/I]
      Modem <=================>Router <=============================> Laptop1
                                   ^
                                   :         
                                   :     [I]wireless connection [/I]
                                   :..................................> Laptop2
    And,
    => Unless you're certain as to current router settings (which includes knowing its current settings / open ports)
    => yes, is best / easiet to simply reset router to manufacturer defaults and then make only changes then needed to support your two laptops
    => Advise working first on the wired connection to Laptop 1
    => Then wireless connection to Laptop 2

    And give a shout if you need any assist as we're all here and happy to help!
  8. jobeard TS Ambassador Posts: 12,224   +120

    unless you explicitly port forward from the router to a specific system, no ports will
    be accessible from the internet which is there intended protection of a router.
    NEVER port forward 135-139 nor 445!
  9. LookinAround TechSpot Chancellor Posts: 7,677   +39

    ^^^^ Good advice (jobeard's post above) to remember whenever changing router settings ^^^^
  10. Manjit Newcomer, in training Posts: 82

    I've managed to set up the wireless router and the software up. Everything seems to be working fine. Thou a little slowly which is to be expected given my brother is also sharing the connection.

    I've tested the connection with DCOMbob and it says that Port 135 is closed. Which is alot better than it being open which is was before. Since having the router Avast has not come up with any DCOM Exploit messages. But i've not adjusted anything on the router settings in the software.
  11. mflynn Newcomer, in training Posts: 2,793

    Should not notice any slowness unless brother is doing Heavy heavy file downloads!

    You did connect directly with cable and not wirelessly right?

    Mike
  12. Manjit Newcomer, in training Posts: 82

    I think he is downloading some stuff plus because he has not used his laptop for a while he has alot of Windows Updates to upload.

    I did connect directly with cables.

    Some final questions before close this epic thread down lol.
    -Can I uninstall Super Anti Spyware/ Malwarebytes/ HJT or is it worth keeping on the laptop to be safe?
    -Also is it worth keeping Spybot and Windows Defender? Do they not do the same job? Should I uninstall one.
    -At the moment i'm using Avast, in conjuction with Online Armour, would I be better off with a better firewall? Or should Avast do the job?

    Once again thanks for your assitance.
  13. mflynn Newcomer, in training Posts: 2,793

    My closing covers most of that.

    After doing the closing if you have questions just ask!

    Thread Closing-------------------------------------------------------------------

    Some of these tools update so often they require downloading again later if needed. But keep and run MBAM and SAS to maintain.

    Remove ComboFix
    Start-Run
    type
    combofix /u
    Hit enter or click OK.

    Please download OTCleanIt http://download.bleepingcomputer.com/oldtimer/OTCleanIt.exe

    Save to desktop.

    This will remove all the tools we used to clean your computer.


    Double-click OTCleanIt.exe. Click CleanUp. Yes to the "Begin cleanup Process?"

    Approve all if prompted by Firewall. Approve Widows Defender or other guards or security programs while OTCleanIt attempting access to the Internet to allow all.

    If prompted to Reboot click, Yes.
    OTCleanit will delete itself when finished, If not delete it by yourself.

    -------------------------------------------------------------------------------------
    Run CCleaner http://www.ccleaner.com/download/builds (get SLIM at bottom no Yahoo toolbar)
    Run twice or more on Cleanup temps, then on left click Registry then Scan for issues also repeat till clean.

    Run ATF-Cleaner http://majorgeeks.com/ATF_Cleaner_d4949.html Temp and Registry, repeatedly until no more found.

    KCleaner ftp://ftp2.kcsoftwares.com/kcsoftwa/files/kcleaner.exe
    Fantastic cleaner.
    -------------------------------------------------------------------------------------
    The issues can and are likely found is in System Restore so do the below

    Start-Programs-Accessories-System Tools-Disk- System Restore and create a new Restore point. Name it "After cleanup at TechSpot".

    Then Start-Programs-Accessories-System Tools-Disk Cleanup
    Click OK to accept C:
    Select all Boxes
    Then click More Options
    Here click System Restore and OK to "Are you sure" and the OK to Run.

    As this runs it clears all but the most recent Restore Point but it does one other thing that can contain infested files and a huge amount of disk space.

    It clears what is known as Shadow copies which are used by specialized back up programs.

    This is if you have the Volume Shadow Copy running which is the default.
    -------------------------------------------------------------------------------------

    Every two weeks or so, run MBAM and SAS until clean.

    They take a while, so leave scanning while you are sleeping working or watching TV. If not done under the gun they can be scheduled not to interfere with computer time.

    If they find something they can not clean, then get back to us.

    Additionally run CCleaner. ATF-Cleaner and KCleaner.
    ----------------------------------------------------------------------------------------
    I have been using ThreatFire for more than a year, it just went from ver 3 to ver 4.

    It was designed to be used with and to co-exist with other Virus scanners.

    Additionally it uses a totally different process to protect. While conventional Virus scanners work from definitions ThreatFire works on recognizing Virus/Malware activity.

    It's like looking at it with 2 sets of eyes and from a different angle.

    It works like some Firewalls do to learn what is good/bad.

    After install it will ask you about everything that could be a security issue. For example the first time you run IE or FireFox it will prompt you. You would answer to approve and remember the setting. From then on no more prompts about IE or FireFox unless the exe changes like in an update.

    As it queries you about the prompt to help you determine to approve or not you can google it with one click.

    http://www.threatfire.com/Download/
    -------------------------------------------------------------------------------------
    Look at http://www.javacoolsoftware.com/spywareblaster.html

    Run SpyBot ocassionally and use the Immunize function.
    http://www.safer-networking.org/en/download/

    I highly reccomend Hostman: Hostman http://majorgeeks.com/HostsMan_d4592.html

    Download install run and allow it to disable DNS Client and select all Host files and then Update and install all host files.

    A Disk Scan (chkdsk) and Defrag are in order.

    Mike