02-04-2011 03:55 PM
Yesterday I about had a heart attack! While doing a Google Search for history on stainless steel flatware that was in the family I clicked on a site...and bam...attacked by a virus
. Didn't think to use the Task Mgr to close just frantically hit the Close while my computer was showing all bells and whistles to let me know I was in trouble. Didn't even think to do a PrtScn...grrrr. Ran a Quick Scan with Avast Free 5 and it indicated: C:\ProductTour.exe Severity High...Threat: Win32:Malware-gen. I had it moved to the Chest. Avast then asked if I wanted a BootScan...and I clicked Yes. Sheesh...several things found including:
1. ... Application Data\Sun\Java\Deployment\ cache ....... \ goog\main.class is infected by Java : Agent - BW [ Trj ]
2. ... Application Data\Sun\Java\Deployment\ cache ....... \ YAHO . class is affected by Java : Jade.A [ Heur ]
3. One I accidentally deleted from my camera as I was trying to increase the size so I could type it in an email after everything was safe. It indicated the Epson printer... spooldriver was corrupted and I don't remember what else it said. Can't figure out how to get to the log for the BootScan.
Ran Malwarebyte's Full Scan after everything was moved to the Avast Chest and it turned up clean.
My Safely Remove Hardware icon is missing from my Task Mgr Notification area. I had a problem with this last week too...so am wondering if I had something then too...but wasn't alerted by Avast or Malwarebytes.
Also wondering which program is best to install for Searching sites...McAfee SiteAdvisor...or Norton's Safe Web program?
Moms...
(XP IE8, Avast Free 5, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0)
02-04-2011 05:23 PM
Moms,
Let's wait and see what LPP suggests, but just some info. If you go with Norton, Windows Defender will be turned off and MalwareBytes should not be run real time (on demand scanner is fine). Norton IMHO does a better job than Windows Defender.
FWIW, I am running Norton Internet Secuirty 2011 on my Win 7 system (paid version) and Norton Secuirty Suite from Comcast on my XP system and I am very pleased with their performance. I have also heard good things about Microsoft Security Essentials (freebie).
A veteran - whether active duty, retired, national guard, or reserve - is someone who, at one point in his or her life, wrote a blank check made payable to The 'United States of America', for an amount of 'up to and including my life.'
02-04-2011 07:19 PM - edited 02-04-2011 07:21 PM
This is my standard response for exploits...
I suggest you follow the instructions here:
http://www.dslreports.com/faq/13616
When you have the required logs, post them here:
http://www.dslreports.com/forum/cleanup
Note that membership at DSLR is not required to post logs in the SCU forum, but it is highly recommended.
I'll be watching for the logs at DSLR.
And don't install anything until you are certain you're computer is clean. While MBAM is an excellent program and on my recommended list, it does not catch everything. Some of the rootkits need other programs.
02-05-2011 01:48 AM
LPP...I won't be home long enough this weekend to do this at one time. I probably won't be able to post until Monday (new baby in our extended family). I've never had to do anything like this...: (. Do you want me to send you a PM or just post here when I'm ready over on DSL?
Assuming that you want me to keep the files in the Avast Chest for now...and not download either program mentioned above to help protect me from nasty virus filled websites that I clicked while doing a Google Search.
Thank you!
Moms...
(E-8...thanks for your input : ).)
02-05-2011 11:09 AM
No need to post here. Just run the programs and post the logs at DSLR. I check there several times a day.
02-05-2011 10:12 PM
Just read through all that I am to do and will start on this tomorrow evening.
I am using Malwarebyte's 1.50.1.1100 and have used it for quite awhile. How do I know if I have it set to Default? Directions say..."When the installation begins, follow the prompts and do not make any changes to default settings." I noticed when going through the settings that one item is unchecked...under General Settings...'Terminate IE during Threat removal.' Also under Scanner Settings...PUP is on 'Show results list and do not check for removal'....PUM is on 'Show results list and check for removal'.
Also in my Quarantine I have 2 Trojan.Agent registry keys sitting there from 3-1-09. Guess I forgot about those so it's safe to say I can delete them by now
.
Moms...
02-06-2011 11:12 AM
If you have MBAM installed the only thing to do is make sure you have the most recent definitions, then run the program.
Yes, you can delete items in quarantine that old.
02-07-2011 11:35 PM - edited 02-07-2011 11:40 PM
LPP...I have all of the scans done..and posted the MBAM over at DSL (Edit to correct) Just figured out how to add other context...heading back over.
Can't figure out how to correct the time as it shows 3hrs ahead...and I entered my Zipcode upon registering.
Thanks for your help!
Moms...
02-08-2011 11:19 AM
I'll be over a DSLR in little bit to check out the logs.
02-09-2011 03:44 PM
Love having our forum and wonderful Experts! Thanks to LPP for making sure my computer was clean
. Now on to adding a couple of good programs to help keep it from happening again!
Moms...
02-10-2011 09:51 AM
Hello moms ![]()
I thought I would just share my personal setup.
1) OpenDNS (Web Filtering @ Moderate "Protects against all adult-related sites, illegal activity, social networking sites, video sharing sites, and general time-wasters." http://www.opendns.com
2) Microsoft Security Essentials (set to scan all inbound and outbound items/drives) http://www.microsoft.com/security_essentials
3) Google Chrome (i use liberkey.com portable version, but listed three links below)
4) The following Google Chrome extensions
That's It ![]()
For 'testing' I use VMWare Server @ http://www.vmware.com/products/server/
Primarily I use Acronis True Image Home 2011 for quick tests @ http://www.acronis.com/homecomputing/products/true
This is all done a Windows 7 x 64 Ultimate ![]()
Stay Safe Everyone & Enjoy the Internet!
02-10-2011 11:23 AM
Thanks George! I'm going to install WOT and perhaps add SiteAdvisor later. I have Norton's Web Safe on FB but reading a little on Open DNS leads me to think it would be a wise selection since it also protects social sites. I'd use the Free version...but need to understand more about it.
Keeping Avast for now and will save the link to MSE to consider later. Also will read up on Acronis...have seen it mentioned before but know nothing about it.
Will these all work for my husband's email too as he uses my computer?
(XP IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0)
02-11-2011 01:15 PM
Moms_hooked wrote:
Thanks George! I'm going to install WOT and perhaps add SiteAdvisor later. I have Norton's Web Safe on FB but reading a little on Open DNS leads me to think it would be a wise selection since it also protects social sites. I'd use the Free version...but need to understand more about it.
Keeping Avast for now and will save the link to MSE to consider later. Also will read up on Acronis...have seen it mentioned before but know nothing about it.
Will these all work for my husband's email too as he uses my computer?
(XP IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0)
Hi Moms,
There might be a few tweaks for various sites including email, mostly around AdBlock.. But you should have no issues. OpenDNS could also cause a issue, but unlikely...
02-13-2011 02:12 PM
I still use SmartZone for email. Tried to figure out how to do a 'Backup' but so far am pretty confused...probably because I was reading to much into it at 3AM. I don't have it on my XP and think my WD Portable Passport might not be large enough. It's an older model and might only be 190GB. Knowing what Mady has to do to her computer makes me think I'm going to have to make some serious changes here sometime in the not to distant future.
(XPHome, IE8, Avast Free 5, Windows Firewall, Malwarebyte's 1.50.1.1100, Windows Defender 1.1.1593.0 and WOT)
|
©2011 Comcast |
Investor Relations |
Press Room |
Corporate Blog |
Privacy Statement |
Visitor Agreement |
Comcast.com Feedback |
Site Map
©2008 Comcast |
Politica de Privacidad |
Acuerdo del Visitante
|