also @ TechSpot: Google, NASA join forces to build quantum computing laboratory

Software found trojans, but said it couldn't find to delete. Ran 5 step

Discussion in 'Virus and Malware Removal' started by lorilev, Feb 19, 2012.

  1. Bobbye Helper on the Fringe Posts: 16,406   +16

    You've mentioned deleting files often. I have lost track! Normally, you would uninstall a program, then use Windows explorer to delete the program folder.

    I am going to recommend that you uninstall the Bitdefender you got from the herman site and request a refund. Use a temporary AV in the meantime.

    If you decide you want Bitdefender again, then download Bitdefender directly from their home site- after I finish trying to get the system clean-and safe!

    You don't have to pay for a full security suite. You can get AV, FW and antimalware programs all free.

    There is some reason the Eset scan won't run- I don't know what it is. Please end the Eset scan and see if you can get Kaspersky to run.

    This should have been a simple matter of just removing one of the multiple AVs and making sure the other was properly updated. Any left over entries could have been removed using script to run through Combofix. But you had already gone ahead with what you did. Now you have a bunch of unidentifiable files on the system that shouldn't be there and can't be removed and so far, it won't run an online virus scan.
  2. lorilev Newcomer, in training Posts: 38

    Should I uninstall the bitdefender first before trying the kapersky? The first eset did run and came back clean-i just forgot to check the archive box.
    Which AV free do you recommend I use now? I'm confused why I need a temporary. I'd like to get something permanent.
  3. Bobbye Helper on the Fringe Posts: 16,406   +16

    Just try running the online scan for now..
  4. lorilev Newcomer, in training Posts: 38

    The link in your previous post #32 to Kaspersky online scan isnt valid any longer. Herman wrote ,me back saying they were giving me a refund with 24 to 48 hours. I think their customer service is just fine. Maybe they got so many complaints that they got their act together??

    I downloaded the Avast from this sites link in the 5 step clean but First I accidentally hit the Uniblue registry clean which was right below the download button. The instruction said to run it first for errors. It said I have over 1700 registry errors to fix. I didn't click to fix them though. Let me know if I should.

    Then, I've uninstalled the Bitdefender and removed all the program files from searching C:\ files and folders. Then I emptied the recycle bin and restarted the computer.
    Now I'm running a full system scan with the AVAST

    It's running like a race car now! What would you like me to do next?
  5. Bobbye Helper on the Fringe Posts: 16,406   +16

    Goodness, you're having all kinds of problems! I don't like what Kaspersky is doing. They have the free scan down again while updating. But it seems you can get the trial version instead. Then, as I think you already experienced, they will bug you to buy the full version! I don't want any of that.

    Here are 2 other online virus scans. Both are free so don't click on any offer to get 'full version.' The difference is that the free version just runs this scan but doesn't offer the AV being resident on the system.
    Panda Free Active Scan
    Trend Micro Housecall for 32bit
    -------------------------------------------------
    Note please: if either of the above scans has a box already checked to remove entries it finds, please uncheck it. I will use a special program to remove the entries and associated files.

    You must be very careful to uncheck any pre-checked boxes on download screens. Ignore the message from Uniblue Registry Cleaner and uninstall it. (Use Add/Remove Programs to uninstall, the Windows Explorer to access Computer> Local Drive(C)> Programs> do a right click> Delete on the program folder. We don't recommend anyone use a registry cleaner as the risks outweighs any benefit. I will remove Avast from my recommended AV since they are pushing this. We stopped recommending Avira for a similar reason.

    But it is ultimately up to the user to check all download screen carefully []before you download and uncheck any offers for toolbars, other programs or browser helpers
  6. lorilev Newcomer, in training Posts: 38

    Is it ok that I have the AVAST AV on now as my permanent protection. It was free. I ran the quick scan with it and it came back saying the computer was clean. That took over an hour though.
    I'll uninstall the Uniblue. Glad I didn't let it run.
    Then run the Panda scan. Will there be a log report to attach from that?
    Thanks for hanging in with me. This is really time intensive.
     
  7. Bobbye Helper on the Fringe Posts: 16,406   +16

    Avast is fine.

    There should be a log or report from any of the online virus scan>>>>unless it doesn't find anything I know the Eset scan doesn't return a log if there are no processes.
  8. lorilev Newcomer, in training Posts: 38

    I've been gone most of the day. Just got back and see that the Panda active scan has been running for 11 hours and is only 12% done! It's moving through files though. It says 2 are infected so far. 0 suspicious and 0 vulnerabilities. I'll let it keep going unless I hear right back, as I'm off to bed, but something is wrong. It shouldnt take this long. The AVAST scan didnt take this long and it found nothing.
    Just checked the computer after letting scan run all night. Now it said 4 viruses detected and still at 12% scan completed. I cancelled the process and just restarted my computer.
    Just ran the other suggested virus scanner you posted called-House Call quick scan option and it came back clean. Then I ran the full scan by House Call and it also came back clean. It took 6 hours for the scan.
    Let me know what's next.
    Thanks.
  9. lorilev Newcomer, in training Posts: 38

    Waiting for new instructions

    Hi Bobbye- it's been a couple of days since I've heard from you. Hope you have forgotten about me...so this is a friendly nudge. Thanks!
  10. Bobbye Helper on the Fringe Posts: 16,406   +16

    I know you've been at this for a while so let's finish up since the online scans are clean.

    Are you having any problems with the system at this point? If you are not, go ahead and do the following:

    Removing all of the tools we used and the files and folders they created
    • Uninstall ComboFix and all Backups of the files it deleted
    • Click START> then RUN
    • Now type Combofix /Uninstall in the runbox and click OK. Note the space between the X and the U, it needs to be there.
      [IMG]
    • Download OTCleanIt by OldTimer and save it to your Desktop.
    • Double click OTCleanIt.exe.
    • Click the CleanUp! button.
    • Select Yes when the "Begin cleanup Process?" prompt appears.
    • If you are prompted to Reboot during the cleanup, select Yes.
    • The tool will delete itself once it finishes.
    -----
    Note: If you receive a warning from your firewall or other security programs regarding OTC attempting to contact the internet, please allow it to do so.

    Note: If any tool, file or folder (belonging to the program we have used) hasn't been deleted, please delete it manually.
    ------------------------------------------
    • You should now set a new Restore Point and remove the old restore points to prevent infection from any previous Restore Points.
    • Go to Start > All Programs > Accessories > System Tools
    • Click "System Restore".
    • Choose "Create a Restore Point" on the first screen then click "Next".
    • Give the Restore Point a name> click "Create".
    • Go back and follow the path to > System Tools.
      [*]Choose Disc Cleanup
      [*]Click "OK" to select the partition or drive you want.
      [*]Click the "More Options" Tab.
      [*]Click "Clean Up" in the System Restore section to remove all previous Restore Points except the newly created one.


    Empty the Recycle Bin

    There may be some of the online scan in the addon section, so you can open the browser> Tools> Addons> in IE, look in both sections of addons currently on and addons previously on and remove Panda, Kaspersky, Eset, Housecall or any of the others you used if still on the system.

    Okay to keep Avast. Remember to check all download screens to remove any pre-checks. Let me know after you run for a few days if any problem comes up.
  11. lorilev Newcomer, in training Posts: 38

    The only thing I notice is that when I first turn on the computer-the startup music is garbled now everytime and the mouse is jumpy and hard to get on the box for entering my password. After the computer starts--everything seems to run smoothly though. But it takes awhile to finish loading up. Seems slow.
    The Combofix /Uninstall didn't work for some reason so I used the IE -programs search -and deleted everything there with the name Combofix attached to it. Then the icon dissappeared.
    Avast wouldn't let me run the OTC either. It kept asking me to run it in the sandbox so I added the program to the sandbox list, but nothing happened and I was never asked to run the clean up. I turned off the Avast and let OTC do it's thing. It ran for a few minutes and asked me to reboot the computer. I sure hope that was a SAFE site Not sure it ever went online to run anyway!!The avast was on when I downloaded the program and saved it to my desktop.
    I'm hesitant to do a system restore until you tell me.
  12. Bobbye Helper on the Fringe Posts: 16,406   +16

    OTC is very safe. I wouldn't have given it to you if it wasn't. Please go ahead with the System Restore.

    Slow loading can be an indication of having too many processes starting on boot. And usually you will also experience a slow shutdown. Only the following need to be checked on the Startup menu:
    Antivirus
    Firewall if using a 3rd party firewall
    Touchpad process if on a laptop
    Network processes if using Citrix/Pure Magic
    Nothing else, including the printer

    1. Call up a programs to use it from All Programs
    2. When you want to Print, click on File> Print in the browser. You can do anything available in the printer from this screen.
    3. Don't use auto-updating except for the AV. I see everyone running the Java updater (jusched) but have 5 or 6 outdated versions on the computer.
    Auto-updates contact the internet several times daily-every day- looking for an update that may come in a month or 6 months.
    ================================
    To remove entries from the Startup Menu using the msconfig utility:
    • Click on Start> Run> type in msconfig> enter>
      [IMG]
    • Click on Selective Startup
    • Choose the Startup tab:
      [IMG]
      All images courtesy NetSquirrel
    • To expand the Command Column, (this shows what the process 'belongs' to) hold left mouse button down on the dividing line on frame above Location and move to the right to expand.
    • Uncheck any processes you do not need to start on boot.
    • Click on Apply> OK when finished.
    NOTE:
    When you reboot the system the first time after making changes using the msconfig utility, a nag message comes up that can be ignored and closed after checking 'don't show this message again.' Remain in Selective Startup to retain those changes.

    Make friends with your computer, but you be the boss- don't let it run you!
  13. lorilev Newcomer, in training Posts: 38

    Ok...all done. I'm the boss of this baby NOW! You are a wonderful person. I would like to do something nice for you ...besides get out off your wall. Do you accept gifts? Have a wonderful evening. I'll let you know in a few days if everything is still working well.
  14. Bobbye Helper on the Fringe Posts: 16,406   +16

    It was my pleasure to help you. The nicest thing you can do for me and the best gift I'd like is for you to remember the things we did and the things we went over. Some of those things are very basic and can be of help to you in the future.
    -------------------------------------------------------------
    All of the following may not be compatible with all versions of Windows or all browsers. They are suggestion only.

    You may find the following helpful: (Links are Bold Blue)
    Tips for added security and safer browsing:
    1. Browser Security
      [o][url="http://www.bleepingcomputer.com/tutorials/tutorial102.htm]Make Internet Explorer safer][/url]
      [o] Use a Site Advisor..
      Have layered Security:
    2. Antivirus Software(only one):
      [o] Comodo AV
      [o]Avast Free
      [o]Microsoft Security Essentials
    3. Firewall (only one)
      [o] Zone Alarm Free
      [o]Comodo Firewall Free
    4. Antispyware/Security: I recommend all of the following:
      [o]Spywareblaster:Protects against bad ActiveX.
      [o]IE/Spyad Restricts bad domains.
      [o]MVPS Hosts files Directs HOSTS file to 127.0.0.1 which is your local computer.
    5. Stay current on updates:
      [o] Windows Updates. You should get All updates marked Critical and the current SP updates.
      [o] Adobe Reade. Uninstall old.
      [o]Java Uninstall old.
    6. Reset Cookies to prevent Tracking Cookies:
      [o]For Internet Explorer: Internet Options (through Tools or Control Panel) Privacy tab> Advanced button> check 'override automatic Cookie handling'> check 'accept first party Cookies'> check 'Block third party Cookies'> check 'allow per session Cookies'> Apply> OK.
      [o]For Firefox: Tools> Options> Privacy> Cookies> check ‘accept Cookies from Sites’> Uncheck 'accept third party Cookies'> Set Keep until 'they expire'. This will allow you to keep Cookies for registered sites and prevent or remove others. (Note: for Firefox v3.5, after Privacy click on 'use custom settings for History.')
      I suggest using the following two add-on for Firefox. They will prevent the Tracking Cookies that come from ads and banners and other sources:
      AdBlock Plus
      Easy List
    7. Do regular Maintenance
      [o]To include Disc Cleanup, Defrag, Error Check/
    8. Remove Temporary Internet Files regularly:
      [o]TFC
    9. System Restore GuideUnderstand Restore Points> why you need to clean and set restore points and what information is in them.
      [*] Practice Safe Email Handling
      [o] Don't open email from anyone you don't know.
      [o] Don't open Attachments in the email. Save to your desktop and scan for viruses using a right click
      [o] Don't leave your personal email address on the internet/ Have a separate email account on free web-based mail.

    Please let me know if you find any bad links.