also @ TechSpot: Mozilla developing Metro-specific Firefox for Windows 8
Welcome to the TechSpot OpenBoards. Please read the FAQ if you have any questions. Sign up or Login to participate.

Go Back   TechSpot OpenBoards > Tech Support > Virus and Malware Removal

Download Now:

3 logs attached from 8 steps to virus & malware removal

Thread Tools Search this Thread
  #1  
Old 12-09-2008
Newcomer, in training
 
Member since: Dec 2008, 6 posts
3 logs attached from 8 steps to virus & malware removal

There are my logs. Thanks!
Attached Files
File Type: txt mbam-log-2008-12-09 (09-17-21).txt (844 Bytes, 3 views)
File Type: log SUPERAntiSpyware Scan Log - 12-09-2008 - 09-41-01.log (5.0 KB, 3 views)
File Type: log hijackthis.log (7.1 KB, 3 views)
  #2  
Old 12-09-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
Please tell us what problems you're having? Throwing out 3 logs with no description of why leaves us a bit short.
  #3  
Old 12-10-2008
Newcomer, in training
 
Member since: Dec 2008, 6 posts
Oops. Sorry about that. I had posted it in another thread, and completely spaced it. I had the "facebook virus" You get an email from a friend saying "Look at this video" etc. And it sends you to a you tube Video. Click on the link and it asks you to download a flash update. I almost never (cant say never anymore) do it, and my instincts told me it sounded fishy, but I was bored and clicked it. (Stupid, yes)

Almost immediately an email is sent out to everyone in my facebook acct. saying the same thing. It also took over my google toolbar. Anytime I would search for something, it would link it to a "virus cleaner" website. Everything else seemed to run ok.

I started the '8 steps' and after the malabytes program, I couldnt use my browser any longer. All my other net based programs(pc anywhere, limewire, etc) that didnt use a browser worked fine. I found that something had inserted a proxy setting( it was 127.0.0.1 PORT 9090) into HTTP setting. I erased that and now the browser is working fine. As you can see by the completed logs, I did finish the 8 steps, and sent them to you all.
  #4  
Old 12-10-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
Thanks. It's helpful to know what problems are being experienced.
The Mbam log is clean-and it shouldn't be.
SAS shows some malware and the Tracking Cookies

But the most important thing I see is NO antivirus program!
I note PCAnywhere from Symantec and a Service for Live Update. But no indication that Symantec/Norton is installed or running.

There' no point in doing the cleaning if you don't get an AV program on the system: This is the first order of business:
Recommended Free Anti Virus:
Avast Free:http://www.avast.com/eng/download-avast-home.html
or
Avira Free:http://www.free-av.com/en/products/1...antivirus.html

You have a wireless connection and mention visiting Limewire. You are a sitting duck to get malware. I advise you to do NO browsing until you get protection on the system and we remove the malware. You should also not use System Restore. Malware can get in the restore points and since the are protected files, the cleaning programs don't remove them. We will drop the old restore points when through cleaning.

When you have downloaded and installed an antivirus program, please update and run a full scan

When through, rerun Malwarebytes, SuperAntispyware and HijackThis and attach the logs.
  #5  
Old 12-10-2008
Newcomer, in training
 
Member since: Dec 2008, 6 posts
There is a antivirus program, I just didnt install it until after the logs. I have AVG 8.0.1. It scans daily, and any file downlaoded via limewire(which I rarely use), I always scan first. Also the malware log was clean because when the malware program shut down my browser for a couple days, I reran the malware when I got it fixed and that was the log from the second run. The first run DID have virus' removed. Ill attach that 1st log to this post.
Attached Files
File Type: txt mbam-log-2008-12-04 (15-23-26).txt (1.7 KB, 1 views)
  #6  
Old 12-10-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
I'm sure you understand that I can only work with what is given. And the log had no AV.

As you see, Mbam did find some malware. Please follow the instruction in the last line of my post.
  #7  
Old 12-11-2008
Newcomer, in training
 
Member since: Dec 2008, 6 posts
Thats no problem. I know you can only go by what I tell you.

I reran the programs this morning. I actually ran superspyware twice. I noticed the first time I ran it I recognized the malware it found in the resgistry before. So after it ran, and I cleaned it out, I reran it again, and I note that the same malware is written in the reg. Any ideas?

Here are the logs, including both supersyware logs
  #8  
Old 12-11-2008
Bobbye's Avatar
Helper on the Fringe
 
Location: Florida
Member since: Mar 2007, 15,043 posts
Here's where the Adware.E404 Helper/Variant-AR threat is:

Have HijackThis remove this entry
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local;<local>

# Alias & packer info:
* not-a-virus:AdWare.Win32.E404.jd [Kaspersky Lab]
* packed with: PE_Patch.UPX [Kaspersky Lab]

Also search for and delete this entry:
%System%\351631

You may know more about this than I do but it is a matter of concern:
Quote:
O16 - DPF: Web-Based Email Tools - http://email.secureserver.net/Download.CAB

Concern is because it is a redirect. By definition: "A Web server that supports any of the major security protocols, like SSL, that encrypt and decrypt messages to protect them against third party tampering. " mail servers move and store mail over corporate networks (via LANs and WANs) and across the Internet.

I just want to make sure you're aware of this and set it up yourself.
Download and run the Norton Removal Tool: The following Services is part of Norton Antivirus:
O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE

You also have PCAnywhere running:
Quote:
O23 - Service: Symantec pcAnywhere Host Service (awhost32) - Symantec Corporation - C:\Program Files\Symantec\pcAnywhere\awhost32.exe

This service should be put on Manual if you are still using it, or the program should be uninstalled if you are not:
Start> Run> services.msc> right click on Symantec pcAnywhere Host Service (awhost32)> Properties> Change Startup to Manual.
When you have finished with the above, run SuperAntispyware and HijackThis and attach logs.
Closed Thread

Similar Topics
Topic Replies Forum
[Resolved] Malware redirecting Google search. Followed 8 steps, attached logs 7 Virus and Malware Removal
8 steps virus removal Logs here 0 Virus and Malware Removal
Followed 8 steps of malware/virus removal. Posting my logs for help 1 Virus and Malware Removal
3 logs attached - 8 Steps to Virus & Malware Removal 8 Virus and Malware Removal
Virus\Malware removal logs attached 25 Virus and Malware Removal

Thread Tools Search this Thread
Search this Thread:

Advanced Search
All times are GMT -4. The time now is 12:52 PM.