SpyWare BeWare! ASAP
May 20, 2013, 11:56:24 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News:
 
   Home   Help Search Calendar Donations Login Register Chat  



Google It!
Pages: 1 [2]   Go Down
  Print  
Author Topic: I THINK I HAVE A VIRUS-I KNOW I DO!!!!!MOVED TO CORRECT FORUM  (Read 3818 times)
0 Members and 1 Guest are viewing this topic.
MrCharlie
ASAP Members
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6588



WWW
« Reply #15 on: January 29, 2012, 01:10:04 PM »

Has that made any difference??  MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
latricedolly
Newbie
*
Offline Offline

Date Registered:January 27, 2012, 08:38:48 AM
Posts: 13


« Reply #16 on: January 30, 2012, 10:32:18 AM »

Well so far, I have not had any redirected searches during my usage.  I am pleased once again!!!  It was very interesting in following the instructions that you was giving, but I don't know what we were doing.  I just know that the procedures were doing something.  Could you give me a summary of what we did to fix the problem that I was having?  I would like to know starting from the very begin when you told me to get a report.  I would appreciate this.
Logged
MrCharlie
ASAP Members
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6588



WWW
« Reply #17 on: January 30, 2012, 10:51:45 AM »

Well from your DDS log, I saw this:

Warning: possible TDL3 rootkit infection !

TDSSKiller is the tool we use to take of this infection.

Bootkit Removal Tool is a tool that will also work but for some reason it wouldn't work on your system.

--------------------------

TDSSKiller found and cured the rootkit:

Quote
14:33:14.0515 3136 Detected object count: 1
14:33:14.0515 3136 Actual detected object count: 1
14:33:24.0015 3136 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - will be cured on reboot
14:33:24.0015 3136 \Device\Harddisk0\DR0 - ok
14:33:24.0015 3136 \Device\Harddisk0\DR0 ( Rootkit.Boot.Pihar.b ) - User select action: Cure
14:33:44.0640 3876 Deinitialize success


We ran TDSSKiller again and it confirms the rootkit is gone.

------------------------------

I had you run RogueKiller to check for any other infections and also check the master boot record  (MBR)
It turned up clean (OK) except for the host file: (which was corrupt)

Quote
¤¤¤ HOSTS File: ¤¤¤
94.63.240.122 www.bing.com


-----------------------------

Quote
+++++ PhysicalDrive0: SAMSUNG HD160JJ/P +++++
--- User ---
[MBR] 54f27e3eb12aa828010f072d5d43f642
[BSP] 11d467b9f31927f29d49c85858b51038 : Windows XP MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 159989 Mo

User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt


---------------------------

I had you run RogueKiller again to restore the host file back to what it's supposed to be.

Quote
¤¤¤ Resetted HOSTS: ¤¤¤
127.0.0.1 localhost


--------------------

So now we'll see how it is.

MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
latricedolly
Newbie
*
Offline Offline

Date Registered:January 27, 2012, 08:38:48 AM
Posts: 13


« Reply #18 on: January 30, 2012, 06:53:20 PM »

Well thanks!!!!  I will work with it some more to see how are things.  But so far, I had not had any problems.  I will post back
Logged
MrCharlie
ASAP Members
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6588



WWW
« Reply #19 on: February 03, 2012, 11:33:09 AM »

How are we doing????

MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
MrCharlie
ASAP Members
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6588



WWW
« Reply #20 on: February 06, 2012, 02:41:42 PM »

Re-opened
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
latricedolly
Newbie
*
Offline Offline

Date Registered:January 27, 2012, 08:38:48 AM
Posts: 13


« Reply #21 on: February 14, 2012, 01:21:18 PM »

It's been awhile, but I had to come back to let everyone know how my computer is doing.  Mr. Charles had given good, easy, and thorough instructions on how to remove the viruses and they worked. I have my computer back to normal and at the same time, gained knowledged on what to do if this should happen again.  Please feel free to use the guidance that Mr. Charles and the forum will give you to solve your computer problems.

Latrice Dolly
Logged
MrCharlie
ASAP Members
Hero Member
*****
Offline Offline

Gender: Male
Date Registered:June 06, 2004, 05:50:23 PM
Posts: 6588



WWW
« Reply #22 on: February 14, 2012, 02:17:08 PM »

Thanks  thumbsup

Take a look at My Preventive Maintenance to avoid being infected again.

Good Luck and Thanks for using the forum,  MrC
Logged

My help is always free here but if you would like to show your appreciation, it will be much appreciated.
Thanks MrC
Pages: 1 [2]   Go Up
  Print  
 
Jump to:  


Powered by MySQL Powered by PHP Powered by SMF 1.1.17 | SMF © 2011, Simple Machines Valid XHTML 1.0! Valid CSS!