Forum Home
Press F1
 
Thread ID: 120815 2011-09-27 20:44:00 HELP - Possible Malware infection - next steps please tuiruru (12277) Press F1
Post ID Timestamp Content User
1234024 2011-09-27 20:44:00 I received a reply to this thread

pressf1.pcworld.co.nz

and followed the link it suggested. At #66 I right clicked 'cos I've got something in the context menu that allows me to scan a URL with Virus Total, which I did. The results of the scan are below

3205
It was pointing at a VBS file. As far as I know I did not download it, and left the site. However, since then things have going flakey.

Each new gmail message opens in a new chrome Window, but GMail settings won't open at all.Double clicking on one of my desktop shortcuts (to my Pictures folder) highlights about five others, and starts a photo program I'd forgotten I had.

I've updated Malware Bytes and am running a full scan at the moment.

The list restore point I made was yesterday.

The last full disk image was made on Sunday

Hmmmmmm - just been thru' those steps described above again and things now seem to be working normally, including getting at g-mail settings.

However, what are the next dos and don'ts?

I'm going to be back and forth from the laptop for a while - in any event, ist a 350+gb drive so MalBy will take a while to complete. Is it going to slow things down or save time if I run Super Anti Spyware at the same time?

Thanks
tuiruru (12277)
1234025 2011-09-27 21:03:00 I run them at once, it's going to take ages anyway so might as well do the lot together and go off and do something else while you wait. pctek (84)
1234026 2011-09-27 21:05:00 I run them at once, it's going to take ages anyway so might as well do the lot together and go off and do something else while you wait.

Thanks pctek
tuiruru (12277)
1234027 2011-09-27 21:20:00 My realtime Event Log Inspector has just posted this:

3206

Is that a clue, or just run of the mill?
tuiruru (12277)
1234028 2011-09-27 21:35:00 I wouldn't worry about those. Thats MSSE. Altho, you shouldnt be using that and NOD32. If that's what that screenshot is of Speedy Gonzales (78)
1234029 2011-09-27 22:17:00 Sounds like a co-incidence to me. http://www.kellys-korner-xp.com/ is not a malware site (I've used their registry fixes etc before without issue) and in fact since that all the links take me to a 503 error I doubt it would have done anything anyway! Agent_24 (57)
1234030 2011-09-28 01:57:00 Hi Guys, sorry for the delay.....

@ Speedy - No, it's not NOD. I've got a little app that monitors Windows' events log on real time and reports any errors it throws up. I came across it ages ago when I thought the hard drive was failing, and I've just left it watching - it can sometimes be quite interesting

@Gary - good to know the site isn't usually associated with malware - it would be great if the script did fix the problem.

Super Antispyware has just finished - here are the results:

3208

The "Critical" ones are a False Positive surely. They've been sat on my pen drive for ages and I needed to clear some space on it so I archived all the contents to my HD some weeks ago

The second is something I created myself trying to hide a file inside a picture (as far as I can remember)

Then there's 237 cookies

M$$E and MalBytes are still going - I think they're slowing each other up. MB is reporting three "hits" but I can't see anyway of seeing what they are whilst the app is running

Is there any way of checking the two VB scripts (one's an UNDO)?
tuiruru (12277)
1234031 2011-09-28 02:44:00 No way of checking the scripts if you can't download them, I get 503 error, not sure about you.

Since they are for XP I wouldn't want to try them on Vista without some good analysis first though (might cause more problems than they are supposed to solve!)
Agent_24 (57)
1234032 2011-09-28 03:24:00 No way of checking the scripts if you can't download them, I get 503 error, not sure about you.

Since they are for XP I wouldn't want to try them on Vista without some good analysis first though (might cause more problems than they are supposed to solve!)

I was worried about using an XP tweak in Vista. I'll have to do some more searching.
tuiruru (12277)
1234033 2011-09-28 04:33:00 Malware Bytes has finished. All it found was three occurrences of the top one that Super Antispyware found (see above), so I zapped 'em just to be sure.

I guess I'l see how it goes

Thanks guys
tuiruru (12277)
1