1.

Solve : Could use some help, might be infected but i'm not sure?

Answer»

I hope this will WORK.  I hit save to desktop but i don't know what happened cuz it's not there, so i took this log instead.  if you need the other one, tell me, and i'll rerun the scan.  Also I didn't remove anything with this scan, i just scanned it as suggested (hope that was the right thing to do).

[email protected] as downloader log:
all ok
# version=7
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6425
# api_version=3.0.2
# EOSSerial=e3ebba6efebc6443b945eafc90d838a3
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2011-03-26 11:42:45
# local_time=2011-03-26 04:42:45 (-0800, Pacific Daylight Time)
# country="United States"
# lang=1033
# osver=5.1.2600 NT Service Pack 3
# compatibility_mode=512 16777215 100 0 80689562 80689562 0 0
# compatibility_mode=3584 16777175 100 0 0 0 0 0
# compatibility_mode=8192 67108863 100 0 0 0 0 0
# scanned=198688
# found=6
# cleaned=0
# scan_time=13495
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(2).exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(3).exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi.exe   a variant of Win32/Adware.Gamevance.AS application (unable to clean)   00000000000000000000000000000000   I
C:\Program Files\iWonEI\Installr\1.bin\jfEIPlug.dll   a variant of Win32/Toolbar.MyWebSearch application (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089734.DLL   a variant of Win32/Toolbar.MyWebSearch application (unable to clean)   00000000000000000000000000000000   I
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089877.DLL   Win32/Toolbar.AskSBar application (unable to clean)   00000000000000000000000000000000   I
Hey Super Dave, i'm having a brain malfunction or something, way back when we started you told me to uninstall iwin games, which i did, but i just realized i didn't uninstall all the games the wife has downloaded to play.  Should i have done that or should i do it now, or will it matter.  Sorry for just catching this. Quote

Should i have done that or should i do it now, or will it matter.
No. It's just iWin games.

Please run ESET again and clean the infections and post the log.ok, thanks.  It may be a day before i can run the eset, but i'll GET there....here you go

C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(2).exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi(3).exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Documents and Settings\Candie\My Documents\Downloads\SetupPlaySushi.exe   a variant of Win32/Adware.Gamevance.AS application   cleaned by deleting - quarantined
C:\Program Files\iWonEI\Installr\1.bin\jfEIPlug.dll   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089734.DLL   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1088\A0089877.DLL   Win32/Toolbar.AskSBar application   cleaned by deleting - quarantined
C:\System Volume Information\_restore{202550A8-7A33-4BCA-9586-051D24DDBF8F}\RP1094\A0090774.dll   a variant of Win32/Toolbar.MyWebSearch application   cleaned by deleting - quarantined
Great. That looks good. If there are no other issues, it's time for some cleanup.

To uninstall ComboFix

  • Click the Start button. Click Run. For Vista: type in Run in the Start search, and click on Run in the results pane.
  • In the field, type in ComboFix /uninstall


(Note: Make sure there's a space between the word ComboFix and the forward-slash.)

  • Then, press Enter, or click OK.
  • This will uninstall ComboFix, delete its folders and files, hides System files and folders, and resets System RESTORE.
************************************************
Clean out your temporary internet files and temp files.

Download TFC by OldTimer to your desktop.

Double-click TFC.exe to run it.

Note: If you are running on Vista, right-click on the file and choose Run As Administrator

TFC will close all programs when run, so make sure you have saved all your work before you begin.

* Click the Start button to begin the cleaning process.
* Depending on how often you clean temp files, execution time should be anywhere from a few seconds to a minute or two.
* Please let TFC run uninterrupted until it is finished.

Once TFC is finished it should restart your computer. If it does not, please manually restart the computer yourself to ensure a complete cleaning.
***********************************************
Looking over your log it seems you don't have any evidence of a third party firewall.

Firewalls protect against hackers and malicious intruders. You need to download a free firewall from one of these reliable vendors.

Remember only install ONE firewall

1) Comodo Personal Firewall (Uncheck during installation "Install Comodo SafeSurf..", Make Comodo my default search provider" and "Make Comodo Search my homepage" and uncheck any HopSurf and/or Ask.com options if you choose this one)
2) Online Armor
3) Agnitum Outpost
4) PC Tools Firewall Plus

If you are using the built-in Windows XP firewall, it is not recommended as it does not block outgoing connections. This means that any malware on your computer is free to "phone home" for more instructions. Simply put, Windows XP contains a mediocre firewall. This firewall is NO replacement for a dedicated software solution. Remember to use only one firewall at the same time.
**********************************************
Use the Secunia Software Inspector to check for out of date software.

•Click Start Now

•Check the box next to Enable thorough system inspection.

•Click Start

•Allow the scan to finish and scroll down to see if any updates are needed.
•Update anything listed.
.
----------

Go to Microsoft Windows Update and get all critical updates.

----------

I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable SHOPPING sites. WOT warns you before you interact with a risky website. It's easy and it's free.

SpywareBlaster- Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
* Using SpywareBlaster to protect your computer from Spyware and Malware
* If you don't know what ActiveX CONTROLS are, see here

Protect yourself against spyware using the Immunize feature in Spybot - Search & Destroy. Guide: Use Spybot's Immunize Feature to prevent spyware infection in real-time. Note: To ensure you have the latest Immunizations always update Spybot - Search & Destroy before Immunizing. Spybot - Search & Destroy FAQ

Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

Also see Slow Computer? It may not be Malware for free cleaning/maintenance tools to help keep your computer running smoothly.
Safe Surfing!Thanks Super Dave, i'll work on the clean up tonite when i got more time.  Should I also uninstall any of the other programs i used like ESET or SysRoot?  Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do?  And last question, regarding firewalls, i have norton internet security which has a firewall so do i need to install one?  Your note says to have only one firewall and i don't want to goof things up.  Thanks, for helping me out. Quote
Should I also uninstall any of the other programs i used like ESET or SysRoot?
Yes. Any tools we use can be uninstalled or deleted. You can keep SAS and MBAM, if you wish. Update them and run them on a regular basis.
Quote
Also i need to delete the mcafee which was downloaded and installed , can i do that thru add/remove programs or is there something special i need to do?
Yes. You should do through add/remove programs. If you have problems removing it, use the McAfee Removal Tool below.
McAfee Consumer Products Removal tool (MCPR.exe)

Quote
norton internet security which has a firewall so do i need to install one?
That's considered a third-party firewall.

Quote
Thanks, for helping me out.
You're welcome. I will lock this thread. If you need it re-opened, please send me a pm.


Discussion

No Comment Found