boards.ie

Go Back   boards.ie > Tech > Computers & Technology > Virus & Malware Removal
Register FAQ Community Calendar Today's Posts Search

Reply
 
Thread Tools Search this Thread
Old 28-11-2010, 18:27   #1
jman0war
Registered User
 
Join Date: Jul 2009
Posts: 171
Caution! Your computer contains a variety of suspicious programs..

Ok it looks like i have some malware.

When i open the odd hyperlink, i get redirected to a page that has an ip in the address bar, and it pretends to do a scan on my computer.
I can't cancel out and have to End Task on iexplorer.exe

It's exactly like this:
http://www.youtube.com/watch?v=VxJlCkX7Spc

Funny thing is, so far its happened exclusively to Guardian (news site) links.

Anyway, i have Malwarebytes Anti-Malware and it only returns some false positives (log file below)

I also use SpyBot S&D, it finds a few things.
I also use Avast (free version, updated) and it finds nothing.
My DNS isn't being redirected and there's nothing in hosts file.

What do you think?



Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5202
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
28/11/2010 05:12:18
mbam-log-2010-11-28 (05-12-18).txt
Scan type: Full scan (C:\|)
Objects scanned: 605811
Time elapsed: 1 hour(s), 21 minute(s), 8 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
C:\BACKUP\Software - Applications\Adobe Photoshop CS3 Extended\Adobe Photoshop CS3 Extended\Crack\Crack\Keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully.
C:\BACKUP\Software - Applications\AdobePremiereCS3\AdobePremiereCS3\Crack\Keygen.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\BACKUP\Software - Applications\Microsoft Office 2007\Office 2007 Keygen.exe (RiskWare.Tool.CK) -> Quarantined and deleted successfully.
jman0war is offline   Reply With Quote
Advertisement
Old 28-11-2010, 18:48   #2
bhickey
Registered User
 
Join Date: May 2005
Location: Athenry
Posts: 1,273
Send a message via MSN to bhickey
Can you first try all those tests again (especially the Malwarebytes bit) in 'Safe Mode with Networking' if you haven't already? Do you think Avast was running and up-to-date when this infection started?
bhickey is offline   Reply With Quote
Old 28-11-2010, 19:22   #3
jman0war
Registered User
 
Join Date: Jul 2009
Posts: 171
Quote:
Originally Posted by bhickey View Post
Can you first try all those tests again (especially the Malwarebytes bit) in 'Safe Mode with Networking' if you haven't already
Yeah, i suppose i'll have to try it.
Quote:
Originally Posted by bhickey View Post
Do you think Avast was running and up-to-date when this infection started?
yes, but there was like 10 minutes between when i downloaded/installed the upgrade (new version), and the mandatory reboot.
So my computer would have been unprotected for a narrow window of time.
jman0war is offline   Reply With Quote
Old 29-11-2010, 06:51   #4
jman0war
Registered User
 
Join Date: Jul 2009
Posts: 171
Nothing found in SAFE mode:


Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 5202
Windows 6.1.7600 (Safe Mode)
Internet Explorer 8.0.7600.16385

28/11/2010 21:13:28
mbam-log-2010-11-28 (21-13-28).txt

Scan type: Full scan (C:\|)
Objects scanned: 453218
Time elapsed: 48 minute(s), 16 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)
jman0war is offline   Reply With Quote
Old 29-11-2010, 06:56   #5
old_aussie
Registered User
 
old_aussie's Avatar
 
Join Date: Nov 2009
Location: Wollongong NSW Australia
Posts: 1,318
You had some common low risk trojans and malwarebytes quarantined and then deleted them.
old_aussie is offline   Reply With Quote
Old 29-11-2010, 08:23   #6
jman0war
Registered User
 
Join Date: Jul 2009
Posts: 171
Quote:
Originally Posted by old_aussie View Post
You had some common low risk trojans and malwarebytes quarantined and then deleted them.
It would be great if that were true, but between my 1st Malware Bytes scan and the 2nd one (done in SAFE mode), i had another link for the Guardian newssite, get re-directed.

The 2nd Malware Bytes scan didn't detect anything.
jman0war is offline   Reply With Quote
Old 29-11-2010, 08:36   #7
bhickey
Registered User
 
Join Date: May 2005
Location: Athenry
Posts: 1,273
Send a message via MSN to bhickey
A common way to get rid of some of the more stubborn viruses is to use the rkill program first to terminate any infected processes before running Malwarebytes again. This gives Malwarebytes (and other virus checkers) a better chance of detecting some viruses that might otherwise stay hidden. Can you try that? Rkill will produce a log in C:\rkill.log so post that too.

Last edited by bhickey; 29-11-2010 at 08:40.
bhickey is offline   Reply With Quote
Old 29-11-2010, 08:38   #8
mp22
Moderator
 
Join Date: Nov 2008
Location: west cork
Posts: 1,744
Do a scan with super anti spyware the free one.
mp22 is offline   Reply With Quote
Reply
  boards.ie > Tech > Computers & Technology > Virus & Malware Removal Top

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off



All times are GMT. The time now is 06:48.