Windows XP Community - XPHeads



returning spywhare and defender pro

microsoft.public.windowsxp.help_and_support


Reply
  #1 (permalink)  
Old 08-11-2008, 04:59 PM
Jspeedo
 
Posts: n/a
returning spywhare and defender pro

I have defender pro. It quarantines "Trojan v7 and I delete it, I do
another scan latter and defender pro quarantines "Trojan v7 again. I
must be doing some thing wrong. Question is, what am doing wrong
causing it to return?




--
Jspeedo
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Sponsored Links
  #2 (permalink)  
Old 08-11-2008, 06:59 PM
Maurice N ~ MVP
 
Posts: n/a
Re: returning spywhare and defender pro
Hello Jspeedo,
Use Windows' Disk Cleanup to delete all temporary files.

Download & save Malwarebytes Anti-Malware from
http://www.besttechie.net/tools/mbam-setup.exe or
http://malwarebytes.gt500.org/mbam.jsp
Double Click mbam-setup.exe to install the application.
Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware
and Launch Malwarebytes Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform FULL Scan, then click Scan.
The scan may take some time to finish,so please be patient.
When the scan is complete, click OK, then Show Results to view the results.
Make sure that everything is checked, and click Remove Selected.
When disinfection is completed, a log will open in Notepad and you may be
prompted to Restart.(See Extra Note)
The log is automatically saved by MBAM and can be viewed by clicking the
Logs tab in MBAM.
Copy & Paste the entire report in a new reply as soon as it has finished.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented
with 1 of 2 prompts.
click OK to either and let MBAM proceed with the disinfection process.
If asked to restart the computer, please do so immediately.

MBAM is an excellent first-line program to use and keep.

Checking for/Help with Malware
http://aumha.org/a/parasite.htm
http://aumha.org/a/quickfix.htm
http://aumha.net/viewtopic.php?t=5878
http://wiki.castlecops.com/Malware_R...:_Introduction
http://mvps.org/winhelp2002/unwanted.htm
http://inetexplorer.mvps.org/data/prevention.htm
http://inetexplorer.mvps.org/tshoot.html
http://www.mvps.org/sramesh2k/Malware_Defence.htm
http://defendingyourmachine.blogspot.com/
http://www.elephantboycomputers.com/...moving_Malware

** Help at malware removal forums: Read the topmost directions at the
forum and Post your logs as required by the forum to one (and only one) of
the following
http://aumha.net/viewforum.php?f=30,
http://www.bleepingcomputer.com/forums/forum22.html,
http://forum.malwareremoval.com/viewforum.php?f=11
http://forums.spywareinfo.com/index.php?showforum=18
http://www.spywarewarrior.com/viewfo...a7ab9210 f7ae, http://forums.subratam.org/index.php?showforum=7, http://forums.spybot.info/forumdisplay.php?f=22 or other appropriate forums for expert analysis, not here.**Make very sure you read and follow the very topmost instructions at theforum you have selected.Do NOT post your logs here.--Maurice NMS-MVP--"Jspeedo" <Jspeedo.2e62ac6@pcbanter.net> wrote in messagenews:Jspeedo.2e62ac6@pcbanter.net...>> I have defender pro. It quarantines "Trojan v7 and I delete it, I do> another scan latter and defender pro quarantines "Trojan v7 again. I> must be doing some thing wrong. Question is, what am doing wrong> causing it to return?>> --> Jspeedo

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #3 (permalink)  
Old 08-12-2008, 04:43 AM
Jspeedo
 
Posts: n/a
Re: returning spywhare and defender pro

Malwarebytes' Anti-Malware 1.24
Database version: 1043
Windows 5.1.2600 Service Pack 2

11:33:39 PM 8/11/2008
mbam-log-8-11-2008 (23-33-39).txt

Scan type: Full Scan (C:\|D:\|E:\|)
Objects scanned: 179464
Time elapsed: 58 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 5
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet
Explorer\SearchScopes\{5b4c3b43-49b6-42a7-a602-f7acdca0d409}
(Adware.OneStepSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\R oot\LEGACY_ONESTEP_SEARCH_SERVICE
(Adware.OneStepSearch) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) ->
Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\W MPlayer\Schemes\f3pss
(Adware.MyWebSearch) -> Quarantined and deleted successfully.

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)




Maurice N ~ MVP;3167511 Wrote:
> Hello Jspeedo,
> Use Windows' Disk Cleanup to delete all temporary files.
>
> Download & save Malwarebytes Anti-Malware from
> http://www.besttechie.net/tools/mbam-setup.exe or
> http://malwarebytes.gt500.org/mbam.jsp
> Double Click mbam-setup.exe to install the application.
> Make sure a checkmark is placed next to Update Malwarebytes'
> Anti-Malware
> and Launch Malwarebytes Anti-Malware, then click Finish.
> If an update is found, it will download and install the latest
> version.
> Once the program has loaded, select Perform FULL Scan, then click
> Scan.
> The scan may take some time to finish,so please be patient.
> When the scan is complete, click OK, then Show Results to view the
> results.
> Make sure that everything is checked, and click Remove Selected.
> When disinfection is completed, a log will open in Notepad and you may
> be
> prompted to Restart.(See Extra Note)
> The log is automatically saved by MBAM and can be viewed by clicking
> the
> Logs tab in MBAM.
> Copy & Paste the entire report in a new reply as soon as it has
> finished.
> Extra Note:
> If MBAM encounters a file that is difficult to remove, you will be
> presented
> with 1 of 2 prompts.
> click OK to either and let MBAM proceed with the disinfection process.
> If asked to restart the computer, please do so immediately.
>
> MBAM is an excellent first-line program to use and keep.
>
> Checking for/Help with Malware
> http://aumha.org/a/parasite.htm
> http://aumha.org/a/quickfix.htm
> http://aumha.net/viewtopic.php?t=5878
> http://tinyurl.com/9ezyj
> http://mvps.org/winhelp2002/unwanted.htm
> http://inetexplorer.mvps.org/data/prevention.htm
> http://inetexplorer.mvps.org/tshoot.html
> http://www.mvps.org/sramesh2k/Malware_Defence.htm
> http://defendingyourmachine.blogspot.com/
> http://tinyurl.com/b9v2h
>
> ** Help at malware removal forums: Read the topmost directions at the
>
> forum and Post your logs as required by the forum to one (and only one)
> of
> the following
> http://aumha.net/viewforum.php?f=30,
> http://www.bleepingcomputer.com/forums/forum22.html,
> http://forum.malwareremoval.com/viewforum.php?f=11
> http://forums.spywareinfo.com/index.php?showforum=18
> http://tinyurl.com/6ldo9t,
> http://forums.subratam.org/index.php?showforum=7,
> http://forums.spybot.info/forumdisplay.php?f=22 or other appropriate
> forums for expert analysis, not here.**Make very sure you read and
> follow the very topmost instructions at theforum you have selected.Do
> NOT post your logs here.--Maurice NMS-MVP--"Jspeedo"
> Jspeedo.2e62ac6@pcbanter.net wrote in
> messagenews:Jspeedo.2e62ac6@pcbanter.net... I have defender pro. It
> quarantines "Trojan v7 and I delete it, I do another scan latter and
> defender pro quarantines "Trojan v7 again. I must be doing some thing
> wrong. Question is, what am doing wrong causing it to return? --
> Jspeedo





--
Jspeedo
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #4 (permalink)  
Old 08-12-2008, 01:04 PM
Maurice N ~ MVP
 
Posts: n/a
Re: returning spywhare and defender pro
MBAM has found some adware. You may well have some other residual malware.

Read the topmost directions at one of the following forums
and post your logs as required by that forum.
Do NOT post your logs here on the MS newsgroups.

http://aumha.net/viewforum.php?f=30,
http://www.bleepingcomputer.com/forums/forum22.html,
http://forum.malwareremoval.com/viewforum.php?f=11
http://forums.spywareinfo.com/index.php?showforum=18
http://www.spywarewarrior.com/viewfo...hp?showforum=7, http://forums.spybot.info/forumdisplay.php?f=22or other appropriate forums for expert analysis, not here.**Make very sure you read and follow the very topmost instructions at theforum you have selected.All the best.--Maurice NMS-MVP--"Jspeedo" <Jspeedo.2e6d386@pcbanter.net> wrote in messagenews:Jspeedo.2e6d386@pcbanter.net...>> Malwarebytes' Anti-Malware 1.24> Database version: 1043> Windows 5.1.2600 Service Pack 2>> 11:33:39 PM 8/11/2008> mbam-log-8-11-2008 (23-33-39).txt>> Scan type: Full Scan (C:\|D:\|E:\|)> Objects scanned: 179464> Time elapsed: 58 minute(s), 34 second(s)>> Memory Processes Infected: 0> Memory Modules Infected: 0> Registry Keys Infected: 5> Registry Values Infected: 0> Registry Data Items Infected: 0> Folders Infected: 0> Files Infected: 0>> Memory Processes Infected:> (No malicious items detected)>> Memory Modules Infected:> (No malicious items detected)>> Registry Keys Infected:> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet> Explorer\SearchScopes\{5b4c3b43-49b6-42a7-a602-f7acdca0d409}> (Adware.OneStepSearch) -> Quarantined and deleted successfully.> HKEY_CURRENT_USER\SOFTWARE\Trymedia Systems (Adware.Trymedia) ->> Quarantined and deleted successfully.>HKEY_LOCAL_MACHINE\SYSTEM\CurrentCon trolSet\Enum\Root\LEGACY_ONESTEP_SEARCH_SERVICE> (Adware.OneStepSearch) -> Quarantined and deleted successfully.> HKEY_CURRENT_USER\SOFTWARE\The Weather Channel (Adware.Hotbar) ->> Quarantined and deleted successfully.> HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\W MPlayer\Schemes\f3pss> (Adware.MyWebSearch) -> Quarantined and deleted successfully.>> Registry Values Infected:> (No malicious items detected)>> Registry Data Items Infected:> (No malicious items detected)>> Folders Infected:> (No malicious items detected)>> Files Infected:> (No malicious items detected)>

Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #5 (permalink)  
Old 08-12-2008, 09:19 PM
Jspeedo
 
Posts: n/a
Re: returning spywhare and defender pro

How do I clean the malwhere up. I've been using Ad-aware SE personal
also.



Jspeedo;3167452 Wrote:
> I have defender pro. It quarantines "Trojan v7 and I delete it, I do
> another scan latter and defender pro quarantines "Trojan v7 again. I
> must be doing some thing wrong. Question is, what am doing wrong
> causing it to return?





--
Jspeedo
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #6 (permalink)  
Old 08-12-2008, 09:51 PM
Maurice N ~ MVP
 
Posts: n/a
Re: returning spywhare and defender pro
Select one of the forums I listed (the list I had in my last reply). My
list has 7 of them pick 1.
You'll get guided help at a forum.
While Ad-aware SE is ok, it is not enough to get serious trojan infections.
No one single tool is enough.

--
Maurice N
MS-MVP
--
"Jspeedo" <Jspeedo.2e7b484@pcbanter.net> wrote in message
news:Jspeedo.2e7b484@pcbanter.net...
>
> How do I clean the malwhere up. I've been using Ad-aware SE personal
> also.
>
>
>
> Jspeedo;3167452 Wrote:
>> I have defender pro. It quarantines "Trojan v7 and I delete it, I do
>> another scan latter and defender pro quarantines "Trojan v7 again. I
>> must be doing some thing wrong. Question is, what am doing wrong
>> causing it to return?

> --
> Jspeedo



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #7 (permalink)  
Old 08-12-2008, 11:35 PM
Jspeedo
 
Posts: n/a
Re: returning spywhare and defender pro

I did this post on
AumHa forums


Maurice N ~ MVP;3168177 Wrote:
> Select one of the forums I listed (the list I had in my last reply). My
>
> list has 7 of them pick 1.
> You'll get guided help at a forum.
> While Ad-aware SE is ok, it is not enough to get serious trojan
> infections.
> No one single tool is enough.
>
> --
> Maurice N
> MS-MVP
> --
> "Jspeedo" Jspeedo.2e7b484@pcbanter.net wrote in message
> news:Jspeedo.2e7b484@pcbanter.net...-
>
> How do I clean the malwhere up. I've been using Ad-aware SE personal
> also.
>
>
>
> Jspeedo;3167452 Wrote:-
> I have defender pro. It quarantines "Trojan v7 and I delete it, I do
> another scan latter and defender pro quarantines "Trojan v7 again.
> I
> must be doing some thing wrong. Question is, what am doing wrong
> causing it to return?-
> --
> Jspeedo -





--
Jspeedo
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
  #8 (permalink)  
Old 08-13-2008, 02:35 PM
Maurice N ~ MVP
 
Posts: n/a
Re: returning spywhare and defender pro
Make sure you follow the steps outlined for you at Aumha, by Bill Castner,
MS-MVP.
All the tools used for malware removal are free. If you will follow-up with
that, it would be to your benefit.

--
Maurice N
MS-MVP
--
"Jspeedo" <Jspeedo.2e7deb4@pcbanter.net> wrote in message
news:Jspeedo.2e7deb4@pcbanter.net...
>
> I did this post on
> AumHa forums
>
>
> Maurice N ~ MVP;3168177 Wrote:
>> Select one of the forums I listed (the list I had in my last reply). My
>>
>> list has 7 of them pick 1.
>> You'll get guided help at a forum.
>> While Ad-aware SE is ok, it is not enough to get serious trojan
>> infections.
>> No one single tool is enough.
>>
>> --
>> Maurice N
>> MS-MVP
>> --
>> "Jspeedo" Jspeedo.2e7b484@pcbanter.net wrote in message
>> news:Jspeedo.2e7b484@pcbanter.net...-
>>
>> How do I clean the malwhere up. I've been using Ad-aware SE personal
>> also.
>>
>>
>>
>> Jspeedo;3167452 Wrote:-
>> I have defender pro. It quarantines "Trojan v7 and I delete it, I do
>> another scan latter and defender pro quarantines "Trojan v7 again.
>> I
>> must be doing some thing wrong. Question is, what am doing wrong
>> causing it to return?-
>> --
>> Jspeedo -



Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 07:42 AM.


Registry Mechanic - Free Scan Now
Driver Scanner 2009 - Free Scan Now




Design by Vjacheslav Trushkin for phpBBStyles.com.
Powered by vBulletin® Version 3.6.7
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Content Relevant URLs by vBSEO 3.1.0

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74