Jump to content

Recommended Posts

Posted
I have no problem with Pete taking a look, or running some scans and posting results for him in a file: nothing ventured, nothing gained! But I wouldn't want to waste his time with probably no infections... so that would be up to Pete!

Feel free .....It's all part of the service we provide.

Not all reports contain Malware.... but most do need some tidying up.

Just following step 2 here: http://freepchelp.forum/t/200448/

and posting the 2 FRST reports in Malware Removal section will give us a good idea if any cleaning needs to be done.

  • Like 3
76c90dd0e79a714317a8daeecc1584d2.png

  • Replies 58
  • Created
  • Last Reply

Top Posters In This Topic

Posted

Hi @starbuck I really hate being a pest. I learn by asking questions. I admire you guys that spend that much time learning about removing malware.

I have thought about trying to become a malware expert, but I don't like starting some thing and not finishing. Not sure I have what it takes to spend that much time. I don't want to cause you any problems my friend,so only answer this if you want to.

Is there a problem running these programs in this order before asking you for help?? I know you like looking for other things, but would it hurt to run these scanners before asking for your help??

Thank you!

Gary!!

Malwarebytes Anti Root Kit

Adwcleaner

Malwarebytes Free

ESET on Line scanner

JTR

Some times you're the wind shield. Some times you're the bug!!:(
Posted
Feel free .....It's all part of the service we provide.

Not all reports contain Malware.... but most do need some tidying up.

Just following step 2 here: http://freepchelp.forum/t/200448/

and posting the 2 FRST reports in Malware Removal section will give us a good idea if any cleaning needs to be done.

Hi, starbuck! I will need a day or ...(two.three, four) before I can sit and work with you. Sunday (today now), Mon. and Tues. all look a little rough! I need to have time and to be able to let the scans do their thing and etc, etc...

 

Right now, been a bit stressed. Do have a Krypto locker attempt on my other email address, though, at Outlook:

Tried to get a shot of the email without touching it, but this is the best I could get: (sorry)upload_2015-3-8_0-21-52.thumb.png.70ddd47a4f62339f6b214e07ac4ecc74.png

"Occasionally, I am lucky enough to see myself! It is always a great revelation to have a minute of insight that reveals how unimportant are the things I thought so important!" ..myself.
Posted
Hi, starbuck! I will need a day or ...(two.three, four) before I can sit and work with you. Sunday (today now), Mon. and Tues. all look a little rough! I need to have time and to be able to let the scans do their thing and etc, etc...

 

Right now, been a bit stressed. Do have a Krypto locker attempt on my other email address, though, at Outlook:

Tried to get a shot of the email without touching it, but this is the best I could get: (sorry)[ATTACH=full]12520[/ATTACH]

A little big, but it is a screenshot, saved to Wordpad.

"Occasionally, I am lucky enough to see myself! It is always a great revelation to have a minute of insight that reveals how unimportant are the things I thought so important!" ..myself.
Posted
Do have a Krypto locker attempt on my other email address, though, at Outlook:

To be honest it doesn't seem to be the CryptoLocker malware.

kryptopay.pl is a Polish bitcoin payment processor for businesses.

Created by a team of young programmers, KryptoPay.pl, has put on speed, transparency and security of transactions using bitcoins.

It's probably a bad choice of business name though.

All the same, if it's junk mail just delete it without opening.

  • Like 1
76c90dd0e79a714317a8daeecc1584d2.png

Posted
Is there a problem running these programs in this order before asking you for help?? I know you like looking for other things, but would it hurt to run these scanners before asking for your help??

Thank you!

Gary!!

Malwarebytes Anti Root Kit

Adwcleaner

Malwarebytes Free

ESET on Line scanner

JTR

Technically there's no problem running these.

But the question is.... are they really necessary?

 

Not all malware is related to Rootkits.

If you run MBAM first it will give you an indication if Adware is present.

If so, then AdwCleaner and JRT can be run to check for leftovers.

MBAM will also give an indication if backdoor malware (rootkits) are present.... if so then MBAR can be run.

Eset Online Scan is basically a scan used for checking on any leftovers after the main removal process has been completed.

 

At the end of the day though.... why go at it like Rambo when you have no idea of what you are dealing with.

Just because those programs may have been run... doesn't mean there won't still be orphan entries that need to be dealt with.

That's the reason for tools like FRST and OTL.

  • Like 2
76c90dd0e79a714317a8daeecc1584d2.png

Posted (edited)

Hi! Pete! @starbuck understand the reason for running FRST and OLT. I'm not trained to read those logs. I don't have the luxury of having a Pete around to check my FRST log when working on a seniors PC.

I like checking for Root Kits first. Free Malwarebytes has a Root Kit feature, but by default it is not checked. Going through like Ranbo is my only option. So far it has served me well here at Golden Oaks. I down loaded MBAM Pro free for a month yesterday on a seniors PC. While it was scanning, a pop up kept flashing in the corner about Trojan Chrome being blocked. When the scan was finished, 2Trojan Chromes and 10 Pups were found.

I did not run any more scans as the PC was performing great after quarantining those! I have found that 95% of the time running MBAM is all that's needed, but I have ran other scans when I thought they were needed. If I find a ASK tool bar, I run JRT. I really like ESET on Line Scanner some times also. I need all the help I can get to keep my seniors happy. Cleaning when you have the PC in front of you is a lot different than helping someone on a help forum like Free PC Help Forum. Thank you for your reply Pete. You are appreciated! Notice scan for Root Kit is not checked on MBAM.;);)

I have noticed that when running MBAM. I'm wondering why it's not a default setting???

 

Capture48.JPG.0a376f78509a0f2338ba8151485cb1fd.JPG

Edited by donetao
Some times you're the wind shield. Some times you're the bug!!:(
Posted
I have noticed that when running MBAM. I'm wondering why it's not a default setting???

The answer is out there!

 

Because rootkit scanning tends to take substantially longer because of how thorough and low-level, Scan for rootkit is disabled by default.

 

It's also fairly new technology, and while this technology has been in use in our Malwarebytes Anti-Rootkit for over a year, we want it used in the field a bit more before we turn it on by default in Malwarebytes Anti-Malware 2.0.

 

Rootkit scanners scan very sensitive areas of the computer and it is not uncommon for the computer to freeze, bluescreen or become unstable while using these type of scanners.

 

Additionally, we're working on some performance improvements for rootkit scanning to speed things up if possible and we may enable it by default in a future release.

 

https://helpdesk.malwarebytes.org/hc/en-us/articles/202350478-Why-is-scan-for-rootkit-off-by-default-

  • Like 4
76c90dd0e79a714317a8daeecc1584d2.png

Posted

Hi! Running MBAR is very fast and I love to see that "Congratulations no cleanup is required"

Thanks for your reply @starbuck !! Root Kits are the worst infection you can have. Not to long ago help forums wouldn't deal with them and recommended back to factory install.

PS You see I study these things;). Would try the malware school, but I just don't think I could handle it for a year and then you are supposed to use that knowledge and I would rather help with other things that I have learned. Thank you for the explanation about Root Kits. I think it's about time they are added in a MBAM scan. That's just MHO!!

Some times you're the wind shield. Some times you're the bug!!:(
Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...