New
#11
Hi,
Follow Carolyn's advice and you will be OK.
Regards,
Golden
RKill is definitely very useful and is updated regularly. It doesn't remove anything, just stops processes that are preventing MBAM from running.
As to trying out ComboFix one of these days, doing so without guidance from someone who has been properly trained is most definitely at your own risk.
You don't need to revert back to an image every time you get a virus, usually, if the AV finds the virus it will get rid of all of it, and if it doesn't, then you revert back.
Plus, I don't even have Acronis True Image or any other image program, and I've heard that some virus's implant themselves into system restore points sometimes, so restoring may not work.
People don't want to reformat and clean install often, so of course they are going to try and get rid of it first with AV's.
eduede, please post your malwarebytes' log. We need to do some further checking to determine if your computer is clean.
ESET Online Scanner:
Note: You can use either Internet Explorer or Mozilla FireFox for this scan. You will however need to disable your current installed Anti-Virus, how to do so can be read here.
Vista/Windows 7 users: You will need to to right-click on the either the IE or FF icon in the Start Menu or Quick Launch Bar on the Taskbar and select Run as Administrator from the context menu.
- Please go herehere to run the scan.
Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.- Select the option YES, I accept the Terms of Use then click on:
- When prompted allow the Add-On/Active X to install.
- Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
- Now click on Advanced Settings and select the following:
- Scan for potentially unwanted applications
- Scan for potentially unsafe applications
- Enable Anti-Stealth Technology
- Now click on:
- The virus signature database... will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
- When completed the Online Scan will begin automatically.
- Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
- When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
- Now click on:
- Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
- Copy and paste that log as a reply to this topic.
Note: Do not forget to re-enable your Anti-Virus application after running the above scan!
Please post the ESET log and Malwarebtes' log as part of your next reply (no attachments please).
I was waiting for the RKill result....it was not posted. @Carolyn; Oops sorry there. What I meant was RKill (not ComboFix). Have used ComboFix previously but am not yet quite familiar with it. RKills seems similar to the DDR script at bleepingcomputer.. Think you ought to start a malware removal sub-forum here. You are in fact trained for it. damien
Hi there
There's ONLY TWO POSSIBLE CORRECT SOLUTIONS for Malware / Virus removal.
TOTAL OS RE-INSTALL. or
RESTORE SAFE BACKUP IMAGE -VIA A BOOT DISK - DO NOT USE THE INFECTED COMPUTER.
Your A/V software needs to prevent infection in REAL TIME. - After the fact analysis is a bit like "Monday Morning Quarter backing" in American Football. In any case by the time you've completed the analysis the stuff is already out of date as new threats can appear almost hourly. Virus and Malware detection is an ever changing target.
Using an Infected machine to do the virus removal itself is a bit like getting the Fox to guard the Chickens.
Cheers
jimbo
Oops again. Sorry Carolyn/Corrine, the previous reply I posted was meant for both of you. Was tired yesterday.
@jimbo;
I was only responding to the inquiry of the OP. Personally, I'd use a system image restore and restore my pc. I'd wipe the hard drive first and restore with MBR but that's just me.
While it seems that the better solution(and the fastest I presume) is what you suggested there are some that wants to know what hit them or what caused the sudden hiccups that broke his/her pc.
Depends on the individual actually on the course of action to take based on the guide/tips that he is given.
On the Rkill, I was curious as to it's nature and performance so I downloaded it and will test it in VirtalBox one of these days. Got curious of "these apps" when I got infected sometime 2007 or 2008 and the mod at MalwareCrypt guided me to the use of an alike app(don't remember what the name was).
AV + HIPS or additional security app should have stopped it but apparently there was a failure there so OP should be making some adjustments to his set-up.
I hope the OP will post the data here.
Cheers:)
damien76, you may want to see Grinler's post about RKill here: RKill - What it does and What it Doesn't - A brief introduction to the program