InterviewSolution
| 1. |
Solve : Looks like I've got it too...? |
|
Answer» Alright, here we go...
There is no option to clean/disinfect, however, we need to analyze the information on the report. To obtain the report: Click on: Save Report As
Copy and paste the Kaspersky Online Scanner Report in your next reply. Note for Internet Explorer 7 users: If at any time you have trouble viewing the accept button of the license, click on the Zoom tool located at the bottom right of the IE window and set the zoom to 75%. Once the license is accepted, reset to 100%.Here's the results from OTMoveIt3: ========== PROCESSES ========== Process explorer.exe killed successfully. ========== SERVICES/DRIVERS ========== ========== REGISTRY ========== ========== FILES ========== d:\windows\Tasks\mqrhbrgx.job moved successfully. ========== COMMANDS ========== File delete failed. D:\DOCUME~1\David\LOCALS~1\Temp\etilqs_Y3L0cFM2wWZFmfj1laKf scheduled to be deleted on reboot. User's Temp folder emptied. User's Temporary Internet Files folder emptied. User's Internet Explorer cache folder emptied. Local Service Temp folder emptied. File delete failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be deleted on reboot. Local Service Temporary Internet Files folder emptied. File delete failed. D:\WINDOWS\temp\Perflib_Perfdata_55c.dat scheduled to be deleted on reboot. Windows Temp folder emptied. Java cache emptied. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_001_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_002_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_003_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_MAP_ scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\urlclassifier3.sqlite scheduled to be deleted on reboot. File delete failed. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\XUL.mfl scheduled to be deleted on reboot. FireFox cache emptied. Temp folders emptied. Explorer started successfully OTMoveIt3 by OldTimer - Version 1.0.7.2 log created on 12212008_202519 Files moved on Reboot... File D:\DOCUME~1\David\LOCALS~1\Temp\etilqs_Y3L0cFM2wWZFmfj1laKf not found! File move failed. D:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\Content.IE5\index.dat scheduled to be moved on reboot. File D:\WINDOWS\temp\Perflib_Perfdata_55c.dat not found! D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_001_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_002_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_003_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\Cache\_CACHE_MAP_ moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\urlclassifier3.sqlite moved successfully. D:\Documents and Settings\David\Local Settings\Application Data\Mozilla\Firefox\Profiles\6gp6iy9l.default\XUL.mfl moved successfully. Now, as for Kaspersky Online Scanner... It downloaded, updated the database, all of that. Ran the scan, then two hours later clicked on 'Save Report As...' and nothing happened, no save prompt or anything, but it did disable the 'Save Report As...' button, so it looks like I'll have to run the scan again and hope it decides to work next time. I did notice that it found one thing in an mp3 file, specifically Trojan-Downloader.WMA.GetCodec.i If that one won't work use this one. Run this online scan. This scanner requires Internet Explorer Use the ESET Nod32 Online Scanner 1. Check the box next to YES, I accept the Terms of Use. 2. Click Start 3. When asked, allow the activex control to install 4. Click Start 5. Make sure that the option Remove found threats and the option Scan unwanted applications is check marked. 6. Click Scan 7. Wait for the scan to finish 8. Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt 9. Add the C:\Program Files\EsetOnlineScanner\log.txt log into your next reply.Here she be: # version=4 # OnlineScanner.ocx=1.0.0.635 # OnlineScannerDLLA.dll=1, 0, 0, 79 # OnlineScannerDLLW.dll=1, 0, 0, 78 # OnlineScannerUninstaller.exe=1, 0, 0, 49 # vers_standard_module=3712 (20081222) # vers_arch_module=1.064 (20080214) # vers_adv_heur_module=1.064 (20070717) # EOSSerial=fd3840ba7bace54892a86d93ad8e0055 # end=finished # remove_checked=true # unwanted_checked=true # utc_time=2008-12-23 04:07:18 # local_time=2008-12-22 08:07:18 (-0800, Pacific Standard Time) # country="United States" # osver=5.1.2600 NT Service Pack 3 # scanned=560628 # found=1 # scan_time=4029 D:\WINDOWS\Help\KEYGEN.EXEprobably a variant of Win32/Agent trojan (unable to clean - deleted)00000000000000000000000000000000
---------- 1. Double click If using Vista Right-Click OTMoveIt and choose Run As Administrator 2. Click on the CleanUp! button. 3. OTMoveIt2 will download a list from the Internet, if your firewall or other defensive programs alerts you, allow it access. 4. Click YES at the next prompt (list downloaded, Do you want to begin cleanup process?)
---------- Use the Secunia Software Inspector to check for out of date software.
---------- Go to Microsoft Windows Update and get all critical updates. ---------- Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC. Concerned about Browser Security? Consider using Mozilla Firefox 3.0 with Adblock Plus and NoScript To prevent unknown applications from being installed on your computer install WinPatrol 2008 * Using Winpatrol to protect your computer from malicious software I suggest using SiteAdvisor. SiteAdvisor rates sites on business practices and spam. Safety ratings from McAfee SiteAdvisor are based on automated safety tests of Web sites. SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox. * Using SpywareBlaster to protect your computer from Spyware and Malware * If you don't know what ActiveX controls are, see here Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future. Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.Amazing skill you have there, evilfantasy! My computer is running like nothing ever happened. Thank you, thank you, thank you!Your welcome. Safe surfing... |
|