Help! Virus and Malware infestation...

Status
Not open for further replies.
To be honest, I don't run much stuff. I use Google Chrome for browsing and have AVG Free edition. AVG blocks every browser redirect exploit that comes up. Every one of them seems to run off javaw.exe and no matter how many times I reinstall Java, if I leave my computer on and unattended on just the Gmail login screen, I will come back a few hours later to an AVG window telling me how many times it blocked something.

It's only an annoyance. Nothing ever gets through. The most annoying thing about my computer at the moment is that since the last Patch Tuesday, all of my personal files and folders have padlocks on them and I have to manually edit permissions in Properties to be able to open, rename, move, delete, upload, or otherwise use them. And that's getting REALLY annoying. But there's no fix. It's a common problem in 64-bit 7/Vista and the only fix is to manually edit permissions in every file and folder. I'll just do them as I go at this point. I have 67GB of junk on here. It'd take me weeks to do them all.
 
This is the first (and hopefully last) time in almost twenty years of home PC usage that I've had to deal with a virus.

Clearly, running Windows based O/S and programs puts the odds against you for a trouble-free lifetime of personal computing.

I copied the Malwarebytes log and e-mailed it to ESET support to show them what their program failed to stop inbound and failed to detect after two full scans. I'm sure they will be thrilled with my polite but to the point message (in fact, they just now e-mailed a "case number" to me).

Thanks again to all of you for your timely and very helpful advice.
 
Originally Posted By: dkryan
This is the first (and hopefully last) time in almost twenty years of home PC usage that I've had to deal with a virus.

Clearly, running Windows based O/S and programs puts the odds against you for a trouble-free lifetime of personal computing.

I copied the Malwarebytes log and e-mailed it to ESET support to show them what their program failed to stop inbound and failed to detect after two full scans. I'm sure they will be thrilled with my polite but to the point message (in fact, they just now e-mailed a "case number" to me).

Thanks again to all of you for your timely and very helpful advice.


http://www.sandboxie.com/

Sandbox your browser and it wont happen again. Free,you've got nothing to lose except having a stress free life computing
wink.gif
 
Sandboxie is a good option.

Also, using Google Chrome can help. See the following web site.

Link To Google Chrome Security Info

Quite a few folks use Firefox too as a web browser. I was a Firefox user for a long time but have been running Chrome now for a few months and like it. There are versions of Chrome for Windows, Linux, and MAC. Same goes for Firefox.

For Email I use Thunderbird both in Linux and Windows.

Both Chrome & Firefox offer a lot of plug-ins - extensions that give additional features - security.
 
Originally Posted By: SrDriver
Sandboxie is a good option.

Also, using Google Chrome can help. See the following web site.

Link To Google Chrome Security Info

Quite a few folks use Firefox too as a web browser. I was a Firefox user for a long time but have been running Chrome now for a few months and like it. There are versions of Chrome for Windows, Linux, and MAC. Same goes for Firefox.

For Email I use Thunderbird both in Linux and Windows.

Both Chrome & Firefox offer a lot of plug-ins - extensions that give additional features - security.




Long time Firefox user here, currently using Chrome. I find it has a fraction of the memory footprint.
 
The presumption is I can have I/E 7 still "exist" on my laptop with no conflicts if I'm running Chrome as my default browser?

And I can set up Chrome with multiple tabs to automatically load my favorite websites (BITOG, etc.)?

And Chrome will run with either XP or Windows 7 O/S?

And would I need to "sandbox" with Chrome?

Thanks, guys.
 
Originally Posted By: dkryan
The presumption is I can have I/E 7 still "exist" on my laptop with no conflicts if I'm running Chrome as my default browser?

And I can set up Chrome with multiple tabs to automatically load my favorite websites (BITOG, etc.)?

And Chrome will run with either XP or Windows 7 O/S?

And would I need to "sandbox" with Chrome?

Thanks, guys.


No, you don't need to sandbox with Chrome. The rest of your post is 100% correct.

Not that sandboxing is not a good idea, but I don't use it with firefox or Chrome. Never had a need to.
 
Originally Posted By: dkryan

And I can set up Chrome with multiple tabs to automatically load my favorite websites (BITOG, etc.)?


I couldn't do that - every time i had to open a new tab, THEN click on the bookmark toolbar (favorite) to load the page in the new tab - FF just opens any bookmark automatically in a new tab - just one click !
idk if there's a way to get that to work in chrome, but i stopped trying after a while. So i stayed with FF.
 
This is the response to my e-mail to ESET detailing the malware that infected one of my laptops and managed to walk right by their internet security software:

"Thank you for contacting ESET Customer Care.

Sorry for the inconvenience. Most malware is installed on a machine by the user without realizing it. Also, some malware can be created specifically for ESET Security Products and others depending on the code of the malware. If a window pops-up that displays anything from a virus/spyware scan, free offers, or even claiming to be Windows antivirus, if there are buttons to click to cancel or close, those are the same as clicking "Install." This is how these programs get past antivirus software. To ensure it won't happen again, just make sure to never click anything inside a pop-up window and instead use the keyboard combination ALT and F4. Holding ALT and pressing F4 will close the window that is on top, which in this case should be the malicious pop-up.

If this resolves your issue or if you need further assistance, please let us know by replying to this email."
 
Originally Posted By: OVERK1LL
Were you able to provide them with the name of the malicious software as presented by MWB?


I copied the entire MBAM log and e-mailed it to them. It included information on the 17 registry keys that were infected, 3 registry values, and 3 files. Part of that log included this:

(Rogue.AntivirusSuite) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\avsoft (Trojan.Fraudpack) -> Quarantined and deleted successfully.

Registry Values Infected:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\gjhpffnq (Rogue.AntivirusSuite.Gen) -> Quarantined and deleted successfully.

Folders Infected:
(No malicious items detected)

Files Infected:

C:\Documents and Settings\DR\Local Settings\Temp\e.exe (Trojan.Dropper) -> Quarantined and deleted successfully.

What was somewhat funny was when the virus was trying to get me to buy antivirstat, either it or my Windows Security program kept saying "BobistheOilGuy" was where I picked the virus up from. Hence, it would not allow me access to the Internet.

Then, strangely enough, an ad for Viagra (of all things) began to run!

As mentioned by ESET, "clicking to close" probably did not really aid my problem. Who knows?

I'll try Google Chrome, get accustomed to it, then teach my wife it's nuances.

The only other site I was on Saturday evening other than BITOG, MSN, and ESPN, was I-tunes store to download a couple of songs. Who knows where in the mix it came from? But at 10 p.m., there it was!
 
Status
Not open for further replies.
Back
Top Bottom