|
02-01-2011, 10:37 AM | #21 | |
Country Gentleman
|
Re: CPU virus question
Quote:
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
|
02-01-2011, 10:47 AM | #22 |
Guest
Posts: n/a
|
Re: CPU virus question
If he can get in as Administrator and get to security updates and use control panel and run Malwarebytes it's not a very good rootkit. Rootkits replace the kernel and you are no longer even running Windows, you are running malware that runs Windows for you, meanwhile it can do whatever it wants with your computer. Keep track of your every keypress, decode encrypted transactions, read any file and hide some from you, turn on your webcam and microphones, anything.
I like Malwarebytes. I just happen to carry SAS around on a thumb drive with me. |
02-01-2011, 11:01 AM | #23 | |
Country Gentleman
|
Re: CPU virus question
Quote:
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
|
02-01-2011, 11:33 AM | #24 |
Have My Own Room
|
Re: CPU virus question
One simple solution that has taken care of some (not all) of these, is a system restore to a date before this happened. In short some are worse than others, meaning some you have to catch before they load, some have to be taken care of in DOS, and some are a restore point away from being gone. Good luck.
|
02-01-2011, 02:37 PM | #25 |
JSR
|
Re: CPU virus question
Download and Install SpyBot Search and Destroy. It's free and it's very good. Make sure to boot into safe mode to run the scans...as some virus', bots, and maleware can stop a scanner from running properly.
|
02-01-2011, 02:43 PM | #26 |
Will herf for food
|
Re: CPU virus question
It's known as "FakeAV". I have fought and beaten this exact issue. A freeware application called HitManPro will find and remove it. Install it while logged in under your profile, reboot into Safe Mode (hit F8 as it is booting up), and run a full system scan.
Many of the other common anti-malware/spyware apps will not work on this one. I have tried MalwareBytes, AVG, SpyBot, Symantec AV, McAfee AV, Trend Micro, and more. HitManPro is the only automated way. I have removed it manually by digging through the registry and tons of DLL files, but I doubt you want to venture into that. Good luck.
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain |
02-01-2011, 02:51 PM | #27 |
Gramps 4x's
Join Date: Oct 2008
First Name: Horatio Seymore Hiny
Location: Boca Raton - North of La Habana
Posts: 8,774
Trading: (8)
|
Re: CPU virus question
Erick, all fantastic advice given to you except the most important.
Here goes Ready? Get a Mac!!! Other than that, not much else I can offer.
__________________
Little known fact: I am a former member of the Village People - The Indian |
02-01-2011, 02:54 PM | #28 | |
Country Gentleman
|
Re: CPU virus question
Quote:
I don't mean to argue with you, and I am sure you have removed it through other programs (gmer is also a good one). I have a lot of experience with this malicious software and have read hours on hours of bleepingcomputer logs to feel confident in my advice.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
|
02-01-2011, 02:58 PM | #29 |
Country Gentleman
|
Re: CPU virus question
Unfortunately, Mac's are not immune to rootkits.
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
02-02-2011, 08:24 AM | #30 | |
Will herf for food
|
Re: CPU virus question
Quote:
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain |
|
02-02-2011, 08:51 AM | #31 |
I'm nuts for the place
|
Re: CPU virus question
I did the Malwarebytes and Comodo AV full scans. It detected the 4 viruses and deleted them, but my wife's IE still doesn't work. Says there no connection to the proxy server. This may be due to Comodo creating a unique IP? She can open all her files again. Thanks for all your help guys! Much appreciated.
|
02-02-2011, 09:02 AM | #32 | |
Country Gentleman
|
Re: CPU virus question
Quote:
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
|
02-02-2011, 09:31 AM | #34 |
That's a Corgi
|
Re: CPU virus question
Copy her files such as documents, favorite, mail settings...
Delete her profile and create a new one until you find the AV software to dig deeper.
__________________
Port Wine & Claret | British Cars | Welsh Corgi's |
02-02-2011, 09:33 AM | #35 | |
On another adventure
|
Re: CPU virus question
Quote:
__________________
Favorites: Arturo Fuente Sun Grown Rosado, Oliva Serie V, CAO La Traviata/Brazilia, Perdomo 10th An. Champagne |
|
02-02-2011, 10:01 AM | #37 | |
Will herf for food
|
Re: CPU virus question
Quote:
For most DSL/Cable providers it is not necessary to use a proxy. Sometimes their install CD points you to one, but that is only for their benefit. They sell the tracking info of where you go, what you browse, and how often you make purchases, and where. They do no collect personal info, but I still don't like participating. Comcast amongst others does this with their proxies. This is why I don't install their CD. You don't need it to get online. Just an IP address, gateway, and a subnet mask. 99% of the time that is automatically provided by DHCP to the cable/DSL modem, so you're good.
__________________
“Eating and sleeping are the only activities that should be allowed to interrupt a man's enjoyment of his cigar;” Mark Twain |
|
02-02-2011, 08:39 PM | #38 |
I'm nuts for the place
|
Re: CPU virus question
|
02-02-2011, 09:07 PM | #39 |
I'm nuts for the place
|
Re: CPU virus question
Found the bastard with Hitman Pro 3.5.8
3 Trojans, 1 Malware, 1 Rootkit, and 3 Tracking Cookie. Question is what do I do now? Delete, quarantine, or ignore? |
02-02-2011, 09:25 PM | #40 |
Country Gentleman
|
Re: CPU virus question
I am not familiar with hitmanpro, but if it found something that tdsskiller did not, I would be wary.
Quarantine it and see what happens. You can always go with my last option which is combofix.exe but let me know before you choose to do this step. I also forgot to mention that you MUST run and save the tdsskiller.exe on your desktop. Or it won't work properly. Here is the basic use for it: http://www.bleepingcomputer.com/forums/topic377240.html
__________________
'It is an honor for a man to keep aloof from strife; But every fool will be quarrelling.' |
Thread Tools | |
Display Modes | |
|
|