Malware/Trojan Help

Eorzea Time
 
 
 
Language: JP EN FR DE
Version 3.1
New Items
users online
Forum » Everything Else » Tech Support » Malware/Trojan help
Malware/Trojan help
First Page 2
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-22 23:51:02
Link | Quote | Reply
 
Sorry I looked through tech support and didn't find anything. Obviously I didn't look hard enough so I apologize for making this thread.

I have avast anti virus and sometime when I'm doing nothing ( I only use my pc for steam and ffxiv) And recently Avast will randomly say its blocked malware and trojans. (like 8-10 all at once)... I ran a malware killer and got 2 files that were infected but now I dont know what to do.

Any help is appreciated and sorry for being such a pc noob.
Offline
Posts: 604
By daddyrabbit4444 2013-07-22 23:59:26
Link | Quote | Reply
 
do what I do every 6months reset your pc back to factory settings, only sure fire way to get rid of everything!
[+]
 Phoenix.Gaiarorshack
Offline
Server: Phoenix
Game: FFXI
user: MiavPigen
Posts: 1245
By Phoenix.Gaiarorshack 2013-07-23 00:29:17
Link | Quote | Reply
 
a little bit more info would be helpfull

try to download
malwarebytes
tdskiller (download link in the middle of the page, not in the sides)
dr web cure it

and scan with those

they don't have any backgrounds scanner its jsut plain on command scanner so they are nice to have around
 Ragnarok.Zohnax
Offline
Server: Ragnarok
Game: FFXI
user: Baelfael
Posts: 545
By Ragnarok.Zohnax 2013-07-23 00:40:34
Link | Quote | Reply
 
Spybot will scan your PC and plug-up some back doors in your browsers and computer to strengthen your resistance to future attacks. No-Script is a nice add-on for Mozilla that way nothing loads automatically on a webpage unless you tell it to.

Your issue sounds pretty standard though, and using some of the above scanners should do the trick. Can also use AVG Free and Ad-Aware Free for scans and removal should they not work. If it starts affecting system processes, let us know.

Also, don't do this:
daddyrabbit4444 said: »
do what I do every 6months reset your pc back to factory settings, only sure fire way to get rid of everything!

That's a last resort if you've got a major *** virus/worm. Otherwise, you can pretty much get rid of most everything that's out there one way or another.
[+]
 Phoenix.Gaiarorshack
Offline
Server: Phoenix
Game: FFXI
user: MiavPigen
Posts: 1245
By Phoenix.Gaiarorshack 2013-07-23 02:02:44
Link | Quote | Reply
 
spybots seach and destroy, ad-aware as well as super antispyware installs a service or other background programs.
which is why i dont recommend mass install these (unnende ressource usage)
they are however good but i will strongly recommand to uninstall them completly after using them to avoid service/backgounds scanner conflicts and/or slowdowns

but then again most ppl dont really care for their pc's peak performance and have all sort of crap running anyway
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 02:20:05
Link | Quote | Reply
 
i already used malwarebytes. ill re-scan. downloading the dr web now. and do you have to buy tdskiller? anyways I was also curious about java updates. I get asked to update it a lot and feel like thats the reason i'm getting these trojan/malware attempts on my pc. not sure though.

Edit: Ty for the help btw. I really appreciate it.
 Phoenix.Gaiarorshack
Offline
Server: Phoenix
Game: FFXI
user: MiavPigen
Posts: 1245
By Phoenix.Gaiarorshack 2013-07-23 02:24:06
Link | Quote | Reply
 
tdskill is a free rootkitt scanner from kaspersky


if your java update leads you to any other site than the official then you sohuld not do it


if you get the message to update on a website ignore it
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 02:33:06
Link | Quote | Reply
 
Didn't ignore it >.> hopefully can get rid of all the crap it put on my pc
Offline
Posts: 991
By Drjones 2013-07-23 08:45:06
Link | Quote | Reply
 
Uninstall Java. It's been a huge vector for malicious code lately.
[+]
 Sylph.Kawar
Offline
Server: Sylph
Game: FFXI
user: Kawar
Posts: 1774
By Sylph.Kawar 2013-07-23 16:58:21
Link | Quote | Reply
 
Leviathan.Phenomena said: »
Sorry I looked through tech support and didn't find anything. Obviously I didn't look hard enough so I apologize for making this thread.

I have avast anti virus and sometime when I'm doing nothing ( I only use my pc for steam and ffxiv) And recently Avast will randomly say its blocked malware and trojans. (like 8-10 all at once)... I ran a malware killer and got 2 files that were infected but now I dont know what to do.

Any help is appreciated and sorry for being such a pc noob.
Run the following programs.

superantispyware
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
full scan btw on both programs

then run malwarebytes
http://download.cnet.com/Malwarebytes-Anti-Malware/3001-8022_4-10804572.html?spi=65ba6127690ffa17af962452087fd906&part=dl-10804572

then again do a full system scan then run
Spybot Search & Destroy 1.6.2
http://www.filehippo.com/download_spybot_search_destroy/5168/

Then post the log of what each program finds on pastebin then give us the link make the paste bin log btw die in 1 month then we have a lot of time to help you.

after running each of the programs clean what ever it finds if you have questions post the log then we can take a look before you clean the files.
 Sylph.Kawar
Offline
Server: Sylph
Game: FFXI
user: Kawar
Posts: 1774
By Sylph.Kawar 2013-07-23 17:00:11
Link | Quote | Reply
 
Leviathan.Phenomena said: »
i already used malwarebytes. ill re-scan. downloading the dr web now. and do you have to buy tdskiller? anyways I was also curious about java updates. I get asked to update it a lot and feel like thats the reason i'm getting these trojan/malware attempts on my pc. not sure though.

Edit: Ty for the help btw. I really appreciate it.
btw java should only ask you to update 1-2 times a month anymore and you may have a problem.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 17:01:08
Link | Quote | Reply
 
Sylph.Kawar said: »
Leviathan.Phenomena said: »
Sorry I looked through tech support and didn't find anything. Obviously I didn't look hard enough so I apologize for making this thread.

I have avast anti virus and sometime when I'm doing nothing ( I only use my pc for steam and ffxiv) And recently Avast will randomly say its blocked malware and trojans. (like 8-10 all at once)... I ran a malware killer and got 2 files that were infected but now I dont know what to do.

Any help is appreciated and sorry for being such a pc noob.
Run the following programs.

superantispyware
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
full scan btw on both programs

then run malwarebytes
http://download.cnet.com/Malwarebytes-Anti-Malware/3001-8022_4-10804572.html?spi=65ba6127690ffa17af962452087fd906&part=dl-10804572

then again do a full system scan then run
Spybot Search & Destroy 1.6.2
http://www.filehippo.com/download_spybot_search_destroy/5168/

Then post the log of what each program finds on pastebin then give us the link make the paste bin log btw die in 1 month then we have a lot of time to help you.

after running each of the programs clean what ever it finds if you have questions post the log then we can take a look before you clean the files.

Ok i'll do this when I get home later or maybe tomorrow. Should I really uninstall java?

Also I full scanned with malwarebytes once. and full scanned and boot scanned with avast once. didnt help. So I will try those other programs you said.

Edit: and by didnt help I mean they found infected files and deleted them but I still get attacked. Aslo I used 1 other software that Ran through everything and did some stuff xD forget its name. Ill update when I get home.

Thank you all for the help.
 Sylph.Kawar
Offline
Server: Sylph
Game: FFXI
user: Kawar
Posts: 1774
By Sylph.Kawar 2013-07-23 17:02:26
Link | Quote | Reply
 
Leviathan.Phenomena said: »
Sylph.Kawar said: »
Leviathan.Phenomena said: »
Sorry I looked through tech support and didn't find anything. Obviously I didn't look hard enough so I apologize for making this thread.

I have avast anti virus and sometime when I'm doing nothing ( I only use my pc for steam and ffxiv) And recently Avast will randomly say its blocked malware and trojans. (like 8-10 all at once)... I ran a malware killer and got 2 files that were infected but now I dont know what to do.

Any help is appreciated and sorry for being such a pc noob.
Run the following programs.

superantispyware
http://www.superantispyware.com/downloadfile.html?productid=SUPERANTISPYWAREFREE
full scan btw on both programs

then run malwarebytes
http://download.cnet.com/Malwarebytes-Anti-Malware/3001-8022_4-10804572.html?spi=65ba6127690ffa17af962452087fd906&part=dl-10804572

then again do a full system scan then run
Spybot Search & Destroy 1.6.2
http://www.filehippo.com/download_spybot_search_destroy/5168/

Then post the log of what each program finds on pastebin then give us the link make the paste bin log btw die in 1 month then we have a lot of time to help you.

after running each of the programs clean what ever it finds if you have questions post the log then we can take a look before you clean the files.

Ok i'll do this when I get home later or maybe tomorrow. Should I really uninstall java?

Also I full scanned with malwarebytes once. and full scanned and boot scanned with avast once. didnt help. So I will try those other programs you said.
For now uninstall java yes once the system is cleaned then one of us can give you the link to the java site to redownload it.BTW what os are you running.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 17:02:56
Link | Quote | Reply
 
Windows 7 64bit
 Sylph.Kawar
Offline
Server: Sylph
Game: FFXI
user: Kawar
Posts: 1774
By Sylph.Kawar 2013-07-23 17:06:09
Link | Quote | Reply
 
Leviathan.Phenomena said: »
Windows 7 64bit
ok thanks so when we need you to reinstall java i can give you the 64 bit link btw a cool note some sites like runescape do not read 64 bit java that well so if you get a message like java is not in installed just uninstall and reset then install the 32bit

also i wanted to ask you to run this tool
hijackthis
http://www.filehippo.com/download_hijackthis/

then paste the log on paste bin then i will run it in a tool i know and it will read the files and tell me if there is something wrong or a better idea.

You should be running all of the programs we tell you in safe mode with networking.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 17:09:20
Link | Quote | Reply
 
Well thats good to know >.> because I haven't/wouldn't of.

Also just to be clear. after I run Full scans with superantispyware and malwarebytes. I will run spybot search and destroy (post log in paste bin) then run hijackthis and post that log in pastebin as well?

And do all of these in safe mode with networking? After uninstalling Java of course
 Sylph.Kawar
Offline
Server: Sylph
Game: FFXI
user: Kawar
Posts: 1774
By Sylph.Kawar 2013-07-23 18:09:26
Link | Quote | Reply
 
Leviathan.Phenomena said: »
Well thats good to know >.> because I haven't/wouldn't of.

Also just to be clear. after I run Full scans with superantispyware and malwarebytes. I will run spybot search and destroy (post log in paste bin) then run hijackthis and post that log in pastebin as well?

And do all of these in safe mode with networking? After uninstalling Java of course
yes and remember when making the paste bin logs you set it to 1 month.You will understand when you see it.
Offline
Posts: 42743
By Jetackuu 2013-07-23 18:27:13
Link | Quote | Reply
 
I used to run spybot all the time, it's added features would probably be worth it for the resources as long as you don't have an older machine.

I use M$ Security Essentials as my A/V and don't have any problems, but I also removed java as I don't need it for ***, and disabled all unused plugins, killed extra services I don't need at startup, use adblock/noscript.

oh and before you run your mouth about M$ Security Essentials Kawar, *** off; I don't give a ***.
 Phoenix.Amandarius
Offline
Server: Phoenix
Game: FFXI
Posts: 3686
By Phoenix.Amandarius 2013-07-23 18:45:26
Link | Quote | Reply
 
You can remove like 99% of the malware out there with combination of TDSSKiller and Combofix. Combofix is the best. Can get them both free from bleepingcomputer.
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:47:46
Link | Quote | Reply
 
combofix can also destroy your computer.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 18:48:00
Link | Quote | Reply
 
Ok, thank you all for the help and advice. Ill try tdsskiller and combofix first. and delete Java. If i still see avast warning me of blocked attacks I will do what kawar told me. And I will probably run superantispyware as well. and delete some tools that I downloaded and dont use.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 18:48:24
Link | Quote | Reply
 
Cerberus.Eugene said: »
combofix can also destroy your computer.

D: And for a newb like me I should probably not use it xD crap
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:50:42
Link | Quote | Reply
 
while were at it, so can hijack this.
Offline
Posts: 42743
By Jetackuu 2013-07-23 18:50:54
Link | Quote | Reply
 
can you screenshot one of the "blocked" attacks?

is it blocking something via a firewall or a program running? if it's the former, that's a good thing, you can change it to not notify you though. (well it's a good thing if it's blocking an incoming attack, if it's blocking an attack trying to go out, then you have a problem).
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:51:23
Link | Quote | Reply
 
Jetackuu said: »
I used to run spybot all the time, it's added features would probably be worth it for the resources as long as you don't have an older machine.

I use M$ Security Essentials as my A/V and don't have any problems, but I also removed java as I don't need it for ***, and disabled all unused plugins, killed extra services I don't need at startup, use adblock/noscript.

oh and before you run your mouth about M$ Security Essentials Kawar, *** off; I don't give a ***.
SE has gotten pretty decent ratings.
Offline
Posts: 42743
By Jetackuu 2013-07-23 18:52:36
Link | Quote | Reply
 
Cerberus.Eugene said: »
while were at it, so can hijack this.
a lot of the tools listed here are over the top and really not for noobs to use.

Not to mention overkill, and a waste of time in most cases, I'd only go through that much trouble if for some reason I couldn't just reinstall, otherwise a reinstall is typically faster than going through a hijack this list.

I can reinstall/drivers/update/software in 3 hours tops, most of which is automated.
[+]
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:53:38
Link | Quote | Reply
 
Best thing short of a sandbox imo is noscript. Running it alongside abp and ghostery and I haven't had more than a tracking cookie in 2 years.

TBH though I'm not sure default ghostery protects you against malware.

It's better to not get infected than to get infected and catch it later.
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:57:41
Link | Quote | Reply
 
Also, uninstalling java will only prevent future problems, not fix your current one. I have it installed but mostly because I have proper noscript settings.
 Leviathan.Phenomena
Offline
Server: Leviathan
Game: FFXI
user: Gawdless
Posts: 1922
By Leviathan.Phenomena 2013-07-23 18:57:43
Link | Quote | Reply
 
I can post a pic of the avast warning in an hour or so. Also should I hit the show details tab?
 Cerberus.Eugene
Offline
Server: Cerberus
Game: FFXI
user: Eugene
Posts: 6999
By Cerberus.Eugene 2013-07-23 18:58:07
Link | Quote | Reply
 
Wouldn't hurt. If its avast its possible you're still infected rather than simply blocking attempts to infect you.
[+]
First Page 2