Go Back   PCMech Forums > Help & Discussion > Networking & Online Security

Need Some Help? Type Your Keywords Here:

Reply
 
LinkBack Thread Tools Search this Thread Rate Thread Display Modes
Old 04-30-2013, 12:51 PM   #1
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
big mistery here ???

I am cleaning up my son's Acer aspire and found win.32 mall ware. with spy-bot. scanned it with MSE and removed it. I did see in c cleaner the clean up scan where it was in the trash to remove.And did so.

How ever spy bot says it is still in the system and can not remove it because part of it is in memory

How can I tell for sure?
seagull is offline   Reply With Quote
Old 04-30-2013, 01:13 PM   #2
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Use Ccleaner to clean out all the temporary files (Windows and IE). Make sure MSE and SpyBot are fully upto date, then reboot and run MSE and SpyBot in safemode.
__________________
Niwa no niwa ni wa, niwa no niwatori wa niwaka ni wani o tabeta.
rjfvillarosa is offline   Reply With Quote
Old 04-30-2013, 02:49 PM   #3
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
MSE said at end of full scan that it was not fully functional in safe mode. Spy bot found it and said it was removed BUT another SB scan in regular mode showed it was still there. Right back where I started #$%$#%$%^
seagull is offline   Reply With Quote
Old 04-30-2013, 03:09 PM   #4
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
This is a great little stand alone scanner that doesn't install it just runs as a free standing app.
http://www.emsisoft.com/en/software/eek/
You also try Windows Defender Offline. Microsoft?s Free Security Tools ? Windows Defender Offline - Microsoft Security Blog - Site Home - TechNet Blogs
With Defender Offline you create a bootable CD that runs a full scan after update, on your harddrive before Windows boots.
rjfvillarosa is offline   Reply With Quote
Old 04-30-2013, 03:24 PM   #5
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
I have a 3 mo old copy of defender but I can't
get it to boot the CD. The bios is set to boot CD. I gave up on that. I will try your other link
Thanks
seagull is offline   Reply With Quote
Old 04-30-2013, 03:50 PM   #6
Staff
Premium Member
 
rjfvillarosa's Avatar
 
Join Date: Sep 2004
Location: Cardiff, Wales. UK
Posts: 6,555
Quote:
Originally Posted by seagull View Post
I have a 3 mo old copy of defender but I can't
get it to boot the CD.
I don't know why but a few people are having problems making the CD bootable. When you run the app it downloads the ISO files and from what I have seen these downloaded files are the problem. I have the 32 and 64bit versions that I made probably about a year ago and they are working fine. I tried to make some new copies a few weeks back and wound up with a bunch of drinks coasters.
rjfvillarosa is offline   Reply With Quote
Old 04-30-2013, 06:13 PM   #7
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
crazy crazy ??
Back to safe mode for the 3rd time. run SBot and it cleans it up. Run sb again to double check.
still not there. Run c cleaner an can see it in the cleanup. Run CC and again it is clean.

Boot into regular mode and run sbot and there it is again.

Is it hiding in firefox? or ???
seagull is offline   Reply With Quote
Old 04-30-2013, 06:48 PM   #8
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,159
Are you setting CCleaner to clean everything out of all browsers? Also, go to Options - Advanced and uncheck the box to only clean temp files older than 24 hours.

Go download HijackThis and run it, post the log.

Try the standalone EmsiSoft.
glc is offline   Reply With Quote
Old 04-30-2013, 07:11 PM   #9
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
I am back to safe mode and have it removed again. When I go to CC advanced everything is unchecked. I have never run a log. I need to read up as to how.
seagull is offline   Reply With Quote
Old 04-30-2013, 07:38 PM   #10
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,159
We have a sticky thread right in this forum about HijackThis logs.
glc is offline   Reply With Quote
Old 04-30-2013, 07:49 PM   #11
Member (10 bit)
 
seagull's Avatar
 
Join Date: Jun 2003
Location: Brookings, OR**Rain forest of the northwest.**
Posts: 639
George I know this is not what you told me to do. I cleaned with SB again and I have it in CC. any thing I can do now in CC ?
seagull is offline   Reply With Quote
Old 04-30-2013, 08:20 PM   #12
glc
Forum Administrator
Staff
Premium Member
 
glc's Avatar
 
Join Date: May 2000
Location: Joplin MO
Posts: 41,159
Why are you resisting the suggestions to run EmsiSoft and get a HijackThis log? All you are doing is going around in circles repeating what is obviously NOT WORKING.
glc is offline   Reply With Quote
Old 04-30-2013, 10:05 PM   #13
Member (10 bit)
Premium Member
 
Join Date: Jun 2008
Location: Northern Wisconsin
Posts: 697
My first concern would be why my anti-malware program didn't catch the bug, win32 infections have been around for many years. The Microsoft Windows Malicious Software Removal Tool is actually very good at removing this type of infection. Some variants of this infection corrupt the system restore files, thus, it returns after you have cleaned and re-booted the machine if system restore is enabled. You may, along with what George and rjfvillarosa suggested, need to turn off system restore before you clean the machine again.
usnavyretired is offline   Reply With Quote
Reply

Bookmarks

Still Need Help? Type Your Keywords Here:


Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On
Trackbacks are Off
Pingbacks are Off
Refbacks are On



All times are GMT -5. The time now is 09:26 PM.
Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2013, vBulletin Solutions, Inc.
SEO by vBSEO 3.6.1