Forum Home
Press F1
 
Thread ID: 128818 2013-01-17 04:46:00 Internet Crime Complaint Center Virus Columbuslee (16989) Press F1
Post ID Timestamp Content User
1323277 2013-01-18 05:22:00 See if trojan remover will remove the reg entries. (simplysup1.com) <- direct link. Update it after you install it, then click on scan. Then select all of the options under the util menu

Did you update the defs for MSE??
Speedy Gonzales (78)
1323278 2013-01-18 06:39:00 if Trojan remover doesn't get them all, download and run rkill/ (www.bleepingcomputer.com) Either one of the 3 blue buttons. Then run the AdwCleaner I posted earlier on as well as the other programs.

If you run Rkill - DO NOT reboot the PC even if asked. Rkill will kill any known malware processes so it can be cleaned out, if you reboot it will start the process all over.
wainuitech (129)
1323279 2013-01-18 12:43:00 Essentials is up to date. But it is frozen - when doing a full scan it froze - I shut it down restarted it comes back at the same space it froze at.

That is why I am afraid to shut down the computer without running a full scan.

After I run the scans us all have suggested I want to install new virus software but I do not know the best one. I am running 3 computers. One home built and fast a laptop and an old one connected to the HDTV.

What should I do?

Will do it after work tonight.

The computer is in protected mode now and I am using it to write this post.
Columbuslee (16989)
1323280 2013-01-18 20:58:00 Most members here would agree that NOD32 is the best antivirus program out there. It isn't free though.

If MSE keeps freezing, and you want to run a antivirus scan, go to www.eset.com and run the online scanner.
Nick G (16709)
1323281 2013-01-18 21:19:00 Ok bit of a decision to be be made.

When MSSE is freezing it could be due to a couple of things,

1. Infections are killing MSSE.
2. MSSE has been damaged due to infections.

As nick suggested do the online scan From Nod32. BUT run that Rkill first.

If you wanted to install Nod32 you will have to remove MSSE, as the two will conflict. The general rule is you cant run more than one Antivirus, but you can run several Antimalware programs.
wainuitech (129)
1323282 2013-01-19 01:32:00 New problem FastScan froze at scheduled tasks (75%) . I guess it is a part of TR 6 . 8 . 5 . Which is frozen .

I also tried to use Revo Uninstaller Pro to uninstall PCTools Spyware Doctor with antivirus 9 . 1 .

Couldn't get it to uninstall but found other programs in the New Programs section: Trojan Remover 6 . 8 . 5 Playopus, Mozilla Maintenance Service, Mozilla Firefox 18 . 0 (x86 en us), Default Tab, CWA Reminder by we-care . com v4 . 1 . 21 . 3, Browser Guard 4 . 0, 7-Zip 9 . 20
Columbuslee (16989)
1323283 2013-01-19 01:35:00 Just ran rill kill: Rkill 2.4.6 by Lawrence Abrams (Grinler)
http://www.bleepingcomputer.com/
Copyright 2008-2013 BleepingComputer.com
More Information about Rkill can be found at this link:
www.bleepingcomputer.com

Program started at: 01/18/2013 08:26:12 PM in x64 mode.
Windows Version: Windows 7 Home Premium Service Pack 1

Checking for Windows services to stop:

* No malware services found to stop.

Checking for processes to terminate:

* C:\Users\Kniess\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (PID: 3992) [UP-HEUR]
* C:\Users\Kniess\AppData\Roaming\DefaultTab\Default Tab\DTUpdate.exe (PID: 6772) [UP-HEUR]

2 proccesses terminated!

Checking Registry for malware related settings:

* System Policy Removed: DisableTaskMgr [HKCU]
* Explorer Policy Removed: NoActiveDesktopChanges [HKLM]

Backup Registry file created at:
C:\Users\Kniess\Desktop\rkill\rkill-01-18-2013-08-26-17.reg

Resetting .EXE, .COM, & .BAT associations in the Windows Registry.

Performing miscellaneous checks:

* No issues found.

Checking Windows Service Integrity:

* No issues found.
Columbuslee (16989)
1323284 2013-01-19 02:50:00 Looks like it killed an infection - could be the one thats causing problems:

C:\Users\Kniess\AppData\Roaming\DefaultTab\Default Tab\DTUpdate.exe

Try running TDSSKiller Direct Link (support.kaspersky.com) See if that finds anymore parts to it, if it finds anything, and asks for a reboot afterwards then let it reboot, it may re-run automatically on the reboot, this is normal.

If you have any Rootkits they can be a pain to remove.


Assuming TDSS doesn't do anything stupid, ( thats the infections altering settings- not TDSS) then run the other antimalware programs.

Theres another program that can be run, but its very powerful, and sometimes depending on what infections you have, when it removes them it makes the system unbootable -- But it can wait for the meantime. Lets see what the above does or doesn't do.
wainuitech (129)
1323285 2013-01-19 13:47:00 I have my computer back!!!! (I think)

Just booted twice and it worked.

If I go with N32 can I run the program on my 3 computers? One not used much. One laptop. One used heavily.

Thanks!!!!!!!!
Columbuslee (16989)
1323286 2013-01-19 18:21:00 Not unless you buy a licence for each PC, although if you buy 3 together (on New Zealand eset site anyway) it's cheaper (NZ$70 for 1, $137 for 3) than buying individually. Richardd150 (13927)
1 2 3 4