View Full Version : Malware removal



Double Edge
06-30-2010, 03:46 PM
Do to recent events, I've got a nasty browser redirect I can't seem to rid myself of. I removed a bunch of other problems and files by running a half dozen cleanup programs but this one is hanging on. AVG gave me a warning "exploit neosploit toolkit 1142" but did not offer to remove it. So far I've run malwarebytes, AVG, ad-aware, superantispyware and housecall. Any other suggestions other than a wipe and restore?

Spartan
06-30-2010, 09:05 PM
I was lucky I guess and able to get rid of it simply by doing a system restore each time it began to show up.

flintysooner
06-30-2010, 09:28 PM
Do to recent events, I've got a nasty browser redirect I can't seem to rid myself of. I removed a bunch of other problems and files by running a half dozen cleanup programs but this one is hanging on. AVG gave me a warning "exploit neosploit toolkit 1142" but did not offer to remove it. So far I've run malwarebytes, AVG, ad-aware, superantispyware and housecall. Any other suggestions other than a wipe and restore?You might check the bleepingcomputer.com forum.

Double Edge
07-06-2010, 05:31 PM
Thanks for the suggestion. I have used bleeping computer before for info but not posted for help on it until now. Might give it up and do a restore instead.

BrettL
07-06-2010, 07:12 PM
I'd try malwarebytes. its the best IMO - never had something I couldn't clean.

http://www.malwarebytes.org/

Double Edge
07-06-2010, 09:31 PM
I ran it first and it removed AV Security Suite and some other files but did not get the browser redirect on my work PC. It did clean up the home machine which also had some problems. Then I tried a few other programs which flagged a couple of more files. I only had the browser redirect left for a few days until I showed up at work this morning and found I had AV Security Suite running again so I ran malwarebytes and I'm back where I was with the redirect. Malwarebytes website says it will clean up AV Security Suite so I'm wondering why it was back. Maybe I picked up AV Security Suite the second time from one of the sites I was redirected to in the last day or so. I gather from bleeping computer the redirect is from a "rootkit" or some such that malwarebytes or most of the other scanners don't touch but I'm not sure.

flintysooner
07-07-2010, 05:30 AM
I am not confident it would remove the rootkit but so far we've had better success with Webroot Antivirus with Spysweeper than anything else for prevention.

okc_bel_air
07-07-2010, 07:28 AM
I used both Malwarebytes and Combofix. If you try Combofix, only use the version found on bleepingcomputer.

CuatrodeMayo
07-07-2010, 09:30 AM
Got the same problem. Malwarebytes doesn't touch it.

skyrick
07-08-2010, 04:03 PM
Try running Malwarebytes or AVG in "Safe Mode". That's what finally rooted out the 16 or 18 trojan horses on my work laptop. But I was left with a computer that wouldn't run anything with an "exe" extension. I ended up re-imaging the computer.

Despite the moderator's reassurances, I'm not sure I trust this site anymore. The only reason I got on today is my iMac at home didn't give me a Defcon 4 warning this time, like it did the last two weeks.

Uncle Slayton
07-08-2010, 06:14 PM
My hard drive is like swiss cheese after over a week of trying to disinfect whatever got on it from here. I've done malware bytes and removed a lot of stuff but there's still damage. My Windows update program won't automatically download anything. Hell, it won't MANUALLY download anything, so I'm sure there's still something on here that's preventing it.

Double Edge
07-09-2010, 05:35 PM
I'm going to conquer mine or overwrite it this weekend.

flintysooner
07-09-2010, 05:49 PM
Did you try GMER (http://www.gmer.net/#rootkit)?

Double Edge
07-09-2010, 06:42 PM
I did and I got blue screen both times I ran it. I dumped a huge number of files from it to an external drive since because it was taking forever to run before it locked up. I'm going to try it again. Maybe in safe mode.

hipsterdoofus
07-14-2010, 01:59 PM
I had problems as well...I'm an IT guy and still have issues with it. What bugs me is that I'm getting the redirects on firefox too, which I've never seen. Can't find anywhere where it is starting up on windows either. May have to format c:\ soon.

flintysooner
07-14-2010, 03:30 PM
Yes, the stuff is getting worse. We used to go a long time between attacks in our little network but now there's something every few days. And the attacks on compromising email and other online accounts seem to be increasing as well.

However, since we switched over to WebRoot we've had no compromised systems.

It's nuts.

SoonerQueen
07-14-2010, 04:03 PM
Now that you all have fixed this webpage, my post count on other forums has gone down. It was really strange, I would post something and within minutes it would show I had hundreds of hits. I knew I had picked up something here because of the virus on this page, because my posts are not all that interesting. Now that you have fixed this page, my hit count is more normal.I don't know who brings these viruses or where they come from, but things work better when they aren't around. Someone just hacked my email account, and it sent emails to a lot of people in my address book trying to sell drugs to my friends and family. You just never know what is going to happen in your online life from one day to the next.

Prunepicker
07-14-2010, 07:04 PM
Do to recent events, I've got a nasty browser redirect I can't seem to
rid myself of. I removed a bunch of other problems and files by running
a half dozen cleanup programs but this one is hanging on. AVG gave
me a warning "exploit neosploit toolkit 1142" but did not offer to
remove it. So far I've run malwarebytes, AVG, ad-aware,
super antispyware and housecall. Any other suggestions other than
a wipe and restore?
I was getting the browser redirect, too. AVG removed over 70 viruses
and they were all in the Java. Try selecting "scan specific files or
folders". Next, select "other". Run AVG and see what happens.

I'm reloading Spybot Search and Destroy (http://download.cnet.com/Spybot-Search-amp-Destroy/3000-8022_4-10122137.html) right now. I removed it
just before the virus hit OKC Talk. I don't know if it would have
worked but I'm doing anyway.

Double Edge
07-14-2010, 09:43 PM
I posted for some help on bleeping computer a couple of weeks ago. Got no response until late last week and they walked me through a dozen steps, scans, then posting results and scanning with other programs and reporting back over a number of days. I think it's a clean machine now. I can't say that's the best way to go because it did take about as much time as it would have to start over but it's fixed.

SoonerQueen
07-14-2010, 10:46 PM
My computer is clean. I use Kaspersky's Internet Security system, and I also use malwarebytes. Just for the heck of it I scanned with Spybot Search and Destroy and nothing showed up. I think once the website was clean, so was my computer. I think we kept infecting ourselves by coming to the site when it was contaminated.. I'm all good now.

flintysooner
07-15-2010, 05:32 AM
I posted for some help on bleeping computer a couple of weeks ago. Got no response until late last week and they walked me through a dozen steps, scans, then posting results and scanning with other programs and reporting back over a number of days. I think it's a clean machine now. I can't say that's the best way to go because it did take about as much time as it would have to start over but it's fixed.I admire your persistence. Great news.

icemncmth
08-08-2010, 07:54 AM
I run Sandboxie on my laptop...best thing since sliced bread.

On my desktop I run a VM session. If it gets infected I just delete it and I am good.

But for the most part I dual boot and run Linux Mint.

flintysooner
08-08-2010, 07:59 AM
I run Sandboxie on my laptop...best thing since sliced bread.

On my desktop I run a VM session. If it gets infected I just delete it and I am good.

But for the most part I dual boot and run Linux Mint.I'm going to look at Sandboxie. Thanks for posting.

Uncle Slayton
08-08-2010, 12:58 PM
MalwareBytes and ComboFix finally seems to have fixed whatever was wrong and the laptop is running fine.

FritterGirl
08-09-2010, 12:02 PM
I started up my old lappy this weekend to start transferring files to my new lappy. Got hit with some bug that has struck AGV flat. Won't even let me open AVG to quarantine, or even download it. The virus pops up in MSE when I only ever use firefox. May try malwarebytes see if it can sweep it. If not, I may be taking it in. I'm not an IT person - AT ALL - so feel like I'm swimming in shark infested waters when it comes to this stuff.

New computer has Semantec, so it's just fine.

demoman2k10
12-28-2010, 02:28 PM
Malwarebytes by Malwarebyes Corporation. www.malwarebytes.org ONE of the BEST offering FREE version and the PRO/Purchased version is EXCELLENT as well. This program recently saved by bacon against a NASTY pest.. That avast!, Pest Patrol, Norton, McAfee's, AVG, and Kaspersky wouldn't touch. I run it about once a week on my primary box but run another program daily. I've got 20 years experience in the IT industry on Multiple platforms so have tried alot of these. Somethings I've learned about protection. ONE Protection at a TIME!! And never rely on just 1 program to keep your box CLEAN. Have a Weekly cleaner and then a different daily cleaner.