1.

Solve : AVG detections?

Answer»

Well, I had AVG turned off (Resident Shield that is) that whole time before and after ComboFix did it's job. I just now turned it back on and the constant trojan notifications have stopped.. so problem solved there. All AVG seems to be running fine now. Is it safe to empty the vault of all those "infections"?

As for Malwarebytes'... I'm still having the same issue. I assume you don't know the problem there, eh?Not sure what's going on with MBAM.

Please do this.

1. Uninstall Malwarebytes' Anti-Malware using Add/Remove programs in the control panel. (if you can)
2. Restart your computer (very important)
3. Download and run this utility. http://www.malwarebytes.org/mbam-clean.exe
4. It will ask to restart your computer (please allow it to).

Now go ahead with the other steps. We can try MBAM again after everything else is done.
Alright, I did the ComboFix uninstall, TFC, and Kscan. The latter's report is posted below.

A couple questions...

The ComboFix uninstall didn't get rid of the icon on the desktop. Should I delete that since all the other things related to it were (probably) uninstalled? And in general... what programs (that you've had me install throughout the process) would you suggest I keep to help keep the computer in shape on a regular basis? Are there any that I can/should get rid of when I'm done?

On a related note (to the remaining ComboFix icon), I downloaded JavaRa to get rid of older Java VERSIONS (when I went through your removal tutorial). When I used the program it said that it got rid of jre1.6.0_07 but when I look in my program files, there's still an 80mb folder there. I assume it did it's job, but I was curious about that.

And finally, it seems several things around my computer have returned to default settings. Is that a "side effect" of ComboFix? Things like the wallpaper changing and icons returning (without performing a system restore) make me a little wary.


As for Malwarebytes', I uninstalled that yesterday after we tried the redownload and installation. I'm pretty sure I've restarted several times since then. Should I restart yet again and then try your link?


--------------------------------------------------------------------------------
KASPERSKY ONLINE SCANNER 7.0 REPORT
 Saturday, July 18, 2009
 Operating System: Microsoft Windows Vista Home Premium Edition, 32-bit Service Pack 1 (build 6001)
 Kaspersky Online Scanner  version: 7.0.26.13
 Program database last update: Saturday, July 18, 2009 09:35:29
 Records in database: 2486942
--------------------------------------------------------------------------------

Scan settings:
   Scan using the following database: extended
   Scan archives: yes
   Scan mail databases: yes

Scan area - My Computer:
   C:\
   D:\
   E:\

Scan statistics:
   Files scanned: 132957
   Threat name: 0
   Infected objects: 0
   Suspicious objects: 0
   Duration of the scan: 01:53:30

No malware has been detected. The scan area is clean.

The selected area was scanned.


---

It seems this is clean One note on it THOUGH. I assume it performed a complete scan, but I can't be sure since I went to sleep and after waking up, the computer was in sleep mode. I assume I wouldn't suspend while the scan was going...

Is there a way to check the number of files on the computer matches what was scanned? Quote

The ComboFix uninstall didn't get rid of the icon on the desktop. Should I delete that since all the other things related to it were (probably) uninstalled?

You can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, C:\combofix.txt and C:\ComboFix-quarantined-files.txt

Quote
And in general... what programs (that you've had me install throughout the process) would you suggest I keep to help keep the computer in shape on a regular basis? Are there any that I can/should get rid of when I'm done?

Keep Malwarebytes and SUPERAntispyware. Update ans run them now and then to be sure nothing else has gotten into the computer.

Also keep CCleaner. You can use it as a daily drive cleaner.

Quote
got rid of jre1.6.0_07 but when I look in my program files, there's still an 80mb folder there.

There should only be one folder inside of the Java folder from the newest version of Java.

Quote
And finally, it seems several things around my computer have returned to default settings. Is that a "side effect" of ComboFix? Things like the wallpaper changing and icons returning (without performing a system restore) make me a little wary.

Yes some of the tools we use reset Windows to it's default settings.


Quote
As for Malwarebytes', I uninstalled that yesterday after we tried the redownload and installation. I'm pretty sure I've restarted several times since then. Should I restart yet again and then try your link?

Try malwarebytes again. If it won't work let me know the exact error you get.Thank you for the advice.

I used the MBAM cleaner and then reinstalled and I still get the same problem. Right after the installation bar is complete a Microsoft Windows notification pops-up that says "Malwarebytes' Anti-Malware has stopped working" then it searches for a solution, then says "A problem caused the program to stop working correctly. Windows will close the program and notify you if a solution is available". Then I press the close button. Then the same notification pops up again. It always happens twice. After that, it says it installed successfully and then whenever it/I try to launch it, the same notification pops up twice again.

The way I got that scan that I provided you before is because I rebooted in safe mode and it worked there.I'm not sure I've ever seen that error with MBAM before. You might want to mention it in their forums. http://www.malwarebytes.org/forums/index.php?showforum=41

Final steps and suggestions.

Use the Secunia Software Inspector to check for out of date software.
  • Click Start Now
  • Check the box next to Enable thorough system inspection.
  • Click Start
  • Allow the scan to finish and scroll down to SEE if any updates are needed.
  • Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX controls are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Alright, I might mention the Malwarebytes' issue there when I get the chance.

I updated everything detected in SSI. I'll be checking out the rest in the near future. I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone. I just want to make sure everything is cleaned out when I uninstall programs. I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded? Lastly, I use the No Script add-on for Firefox sometime. I got that malware when I had it disabled. I dislike how it restricts so many things on websites, but I've never had virus issues while using it. What's you opinion on that add-on?

And about the Java updates. I now have 3 folders in C:\Program Files\Java  (jre6, jre1.6.0_07, jre1.6.0_13). Since you said I should only have 1, should I delete any of them?



Thank you so much for your time and help Kevin. I'm very grateful. Quote
I also wanted to know if there is a safe registry cleaner that you'd recommend or if you think it's best to leave it alone.

Unless you really know what you are doing then leave them alone. Use Revo Uninstaller to completely and safely remove software.

* Open Revo and let the list populate (can take several seconds to finish).
* Right click what you want to uninstall and choose Uninstall
* Next choose Advanced then click Next
* This will (try to) launch the programs built in uninstaller and go through the normal uninstall process.
* If the uninstaller fails just continue on with the Revo instructions.
* Once complete: In Revo Uninstaller click Next and Revo will scan the registry for LEFTOVERS.
* This scan can take several seconds.
* Once the results are shown look at each one to ensure they are all related to the program that was uninstalled.
* Choose Select All then click Delete
* Click Next and Revo will scan for any files or folders that were not removed.
* If any files/folders are found choose Select all > Delete

Quote
I was also curious about the Kapersky Scan. Is there anything I need to clear out that it downloaded?

I think there is a Kaspersky entry in Add/Remove Programs you can uninstall.

Quote
Lastly, I use the No Script add-on for Firefox

I'm the same as you. NoScript is a great add on but it blocks too much so I don't use it. I rely on Spywareblaster and Spybots Immunize. Those and Avast antivirus have kept me safe.

Quote
(jre6, jre1.6.0_07, jre1.6.0_13)

The newest version is Sun Java Runtime Environment 6 Update 14 so you are still out of date.

First install the new Sun Java Runtime Environment

Note: UNCHECK any pre-checked toolbar and/or software offered with the Java update. The pre-checked toolbars/software are not part of the Java update.

Be sure to close all browser windows before beginning the install.

Remove the old version(s)

Download JavaRa
* Unzip the file and open the JavaRa.exe
* Click Remove Older Versions
* JavaRa will search for and remove any outdated version of Java and remove any that are found.
* Click ADDITIONAL Tasks
* Place a check next to Remove Useless JRE Files and click Go
* Exit JavaRa
* Delete the JavaRa files from the Desktop

Additional Note: The Java Quick Starter (JQS.exe) adds a service to improve the initial startup time of Java applets and applications. To disable the JQS service if you don't want to use it, go to Start > Control Panel > Java > Advanced > Miscellaneous and uncheck the box for Java Quick Starter. Click OK and restart your computer.

Quote
Thank you so much for your time and help Kevin. I'm very grateful.

Your welcome. Let us know if anything else comes up.





Discussion

No Comment Found