From collectibles to cars, buy and sell all kinds of items on eBay
aAdvanced Search
Last Post Nov 5, 2009 7:03 AM by: *_dash_*
Replies: 15
)
mstuf
Posts: 419

Problem Gone ? What to Do Now ??

Oct 23, 2009 7:58 PM
Good Evening -

I recently opened a link in an email from the Wife of a Trusted Source -- He's been having some Health Problems and I assumed that it was about a new development of his health. The Link opened a Canadian Pill Pharmacy ad -- and I knew what I had done.

I ran my AVG -- with no result -- also MalwareBytes - Bit Defender - Spybot -- Windows Malicious Remover. Nothing found but, across the next days - my browser and computer operation became slow, links were being Hijacked, and my computer didnt want to shut down. A friend suggested that I let Spyware Doctor run a Scan -- It found a few warning low risk items and it found Trojan-Spy.Zbot.

I didnt buy the Spy Doctor -- when I opened the page to see the Amount -- my AVG popped up a Warning Page that scared me off. I have a friend that warns of some free scan sites that Expoit the Granted Access.

My Son performed a system restore back before the email date and at this point This was completed about 90 Minutes ago. All seems GOOD. Computer pages are Loading Faster -- Browser working Faster and Links are not Hijacked.

What should I do now ? Where is the Malicious File / Program ? If its still in the Computer, how do I keep it from re-activating ?

Should I Clear all the System Restore Points that were after the one I used ?

This is New Territory for me -- I've never had to use system Restore before. I Can't seem to find this issue addressed anywhere in the Restore threads or Spyware Removal with Restore threads.

Thank You -- Your shared knowledge would be appreciated
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
silverht
Posts: 6
(1 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 23, 2009 8:37 PM
I would clear all restore points then goto Microsoft's Live One Care. Then after that I sujest replacing AVG with "Avast!". I found "Avast!" to be a better "freeware" AV. It updates more often and finds more malwares.

Jon Nailor
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(2 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 1:35 AM
Thank You Jon --

Been Going for 6+ Hours Now without problem. - I think I'm Going to let it Run Tonight and do a Final AVG Deep Scan --- Then Tomorrow, I'll get rid of the Restore Files if all still looks good and I'll try Avast. Another Friend of mine has recommended it too!

When you escape from something like this it always reminds you to Clean Up - Clean Out - Back Up etc.

This is the Weekend -- Rain Rain Rain

Thanks for the Suggestions
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
dash_*
Posts: 1,085
(3 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 3:17 AM
I'd recommend Avtivir as I prefer it to Avast. It has slightly better virus detection rates (in recent tests) but either way they're both much better at picking up viruses than AVG.

There shouldn't be a reason why simply opening a spam email such as the one you did should give you a virus, not unless you're using a fairly old and unpatched email program. What email program do you use?

I personally wouldn't bother with OneCare. It didn't do very well in the latest virus tests I mentioned. It was one of the worst performers. It's very unlikely running it before running Antivir or AVG will achieve anything.

"Should I Clear all the System Restore Points that were after the one I used ?"

I would, once you're sure you're infection free, as the trouble with System Restore is that it can backup and restore a virus.

There's a link to tp a pdf of the latest virus tests on this page if you wish to compare antivirus programs. Link
Of the ones discussed here the results were Ativir (Avira) 99.4%, Avast 98%, AVG 94%, and OneCare (Microsoft) 90%.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
black*max
Posts: 13,518
(4 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 5:49 AM
FYI "spy doctor" is spyware, "spyware doctor" is a good program.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(5 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 11:05 AM
Hello Dash -- Thanks for the suggestion -- and Input

All was Better -- but after more use, not gone -- my guess is just starting over.

My Computer is Faster and shutting down properly when ordered to -- but still getting browser Redirects.

My Email still comes through AOL -

I had already Installed Avast and let it run its initial Boot Scan and it Found Nothing.

I didnt just open the mail -- I opened the Link in the mail. Funny but theres probably only one other sender that I would have just Clicked on the link for. I've tried to contact the senders -- she may not even have known it sent anything but I've had no reply from either her or spouse so, I'm guessing they are in shut down and repair mode.


BLACK MAX -- In my haste and need of sleep I did say Spy Doctor the secord time but I meant Spyware Doctor, a link I found on a MajorGeeks webpage as a recommended Scan. I'm always leary of those FREE SCAN's. Its the one that finds Trojan-Spy.Zbot. Nothing Else has found anything. All the other scans are clean.

-----------

I have to go to town this morning -- but will return this afternoon -- I'm following all the steps on GeekstoGo.com shown for Malware and Virus Removal -- I've completed 1-5. I'll run the Rootkit - step 6 thing. At that point I plan to Scan with Spyware Doctor again and see if it still finds the Same. Then, if so ask for Help through the Forum. I registered there yesterday just in case. I like the attitude there by description and have read several threads. Seems like me. At least thats my plan at this point.

As I said above, the only current indication of an infection is Browser Redirects from Google when searching for Virus / Malware Related information. I dont notice it on Links at Commercial Sites - Weather Sites - Sprint Car Sites etc etc.


I do appreciate everyones time to share info.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
dash_*
Posts: 1,085
(6 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 4:00 PM
mstuf:
"My Email still comes through AOL"


I'm actually not sure what that means.... do you use an email program or a browser or are you using the old AOL browser?
Even clicking on a link in the email shouldn't have got you infected. Not if you're using a recent browser (which is all patched up) and running a decent antivirus program. You should still have been safe.
I click on all sorts of suspect links and visit all sorts of evil sites.... Every so often Antivir warns me about nasties in my internet cache and blocks them, but I've never had a virus. At least not in the last ten years.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(7 of 15)

Re: Problem Gone ? What to Do Now ??

Oct 24, 2009 5:02 PM
I have Aol Security 9.0 - The Email is all I use AOL For. I'm not real wild about its invasive / takeover - and when I get a New Computer -- I may finally dump them. I've had the Email address forever and its Everywhere - I need to look and see if AOL has a Forwarding Feature -- it would be major to send all my business and other contacts an email that would inform them.

I read that there is a Company that Converts AOL Stored Email / File Cabnets to a form that can be read / searched / Saved. I have almost 100000 Received and Send Emails in Storage -- and I do search the for stuff at least a couple times a month/

I Browse and Work online with IE7 -- Havent Moved to 8 yet -- My Daughter said it ran slower on her computer and something about a Search / Indexing file that takes over and runs hard drive for long periods of Time ( as much 40 Minutes ).

At the time I opened the suspect file, I was using daily updated AVG 8.5.

I have no proof that was the Culprit but Several things made me Suspicious.

A Link for a Pharmacy / Pill Co. in an email from this person would just never happen intentionally -- As Soon as I opened and Closed it - I clicked the Report to Spam Button and Looked down to see my Hard Drive Light on and not stopping. I quick Closed Everything - rebooted - and ran AVG Full scan and More but found nothing -- Thought all was OK but within a day I started Seeing Slow Down and Brower Redirects - IE cannot load this page messages etc --

Just Got Home -- A trip to town on a Saturday is alway twice as long as you think its goint to be --
I'm Going to Run Spyware Doctor Scan Again and see if it still gives same results after all the Steps I've taken.

Will Report ! Thanks
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(8 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 2:44 AM
Just an Update -- I said I would report =-

The Problem was NOT Gone -- Within another day, My Browser began redirecting even worse -- my computer Refused to shut down when ordered -- I had no access to Task Manager etc.

My Case at GeekstoGo came up and a very helpful - very dedicated tech began helping me -

Across the last 10 days I've downloaded and run more stuff than I ever did in the history of the computer.

Still Working at it but the above mentioned problems are gone. We are stil searching for remaining problems and havent cleaned up yet.

Tonight -- I recieved another Email from the Account that sent the first one with the link I opened.
Its not the Same URL -- and this one is just text -- not a live clickable link. The CC Names in the info bar are the same. Those recognized ISP's etc are part of what made me trust the link in the first email. I wont open it but I did save the URL. I reported it to the Geeks to Go threads. Not sure, but if it were to contain the same malware that it might provide valuable information about what all we were fighting to someone who knows how to deal with it safely.

Nasty Stuff

Thanks for Looking
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
zdoghouse
Posts: 120
(9 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 8:42 AM
dload and run malwarebytes


malwarebytes.org
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(10 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 12:05 PM
dload and run malwarebytes

Yes, Malware bytes is part of my standard weekly cleanup --it found nothing -- nor did SAS.

We've been doing sites like Combofix - a Rootkit Analysis Site - one of Kaspersky's tools etc. I send Log files of the Reports. Most of those sites are over my knowledge level. The Set ups and Check boxes to start them offer questions / options that I dont comprehend. GeekstoGo Website has been a Blessing and offers huge amounts of threads and info about removing and recovering from Malware and Viruses.


Thanks for the suggestion --
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
*_dash_*
Posts: 153
(11 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 4:46 PM
For all the time you've spent trying to fix the problem so far you probably could have backed up all your data, reformatted the hard drive and re-installed Windows. That's probably what I'd do and at least you'd have a nice clean installation.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(12 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 8:44 PM
I have always wished I could - but I lack the confidence to try again. Previous WinXX ventures and other such Reloads have been disasters. Never has one been even equal in performance again to what I was trying to wash. Some Items never worked again properly and each time I ended up just moving to a another computer or buying another.

I lack some understanding of Computer Operations -things like Partitioning - Reinstalling Drivers - Specified Location Options - Re-establishing my Network ( that I still feel somehow lucky is working - I spent more than a Month getting that nightmare functioning ) - etc etc.

It always asks me to make a choice of something that I wasnt prepared to answer and I know better than to Guess.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
*_dash_*
Posts: 153
(13 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 4, 2009 11:22 PM
At the risk of being presumptuous, I'd be thinking now's the time to learn.
The reason for slower performance is possibly due to not re-installing the correct drivers. Windows will run most hardware on it's generic drivers, often it'll have the correct drivers built in, and I can't think of any other likely reasons for a fresh install running slower than an older one. Plus if you reloaded Windows over the top of itself rather than wiped the drive clean and started again there's a good chance it never actually fixed any of the problems. It may have even created new ones.

Once you've done it once you won't look back. The hardest part is the preparation, finding out what all the bits inside the PC are, downloading the latest drivers and burning them to CD etc so you've got them ready to install after you've re-installed Windows. From there (assuming you're using a standard Windows installation CD) it's just a matter of booting from the Windows disc and making sure you follow the correct prompts.
If you do a Google for PC Wizard and install it, it'll tell you everything you need to know about your hardware. There's also programs which will back up your current drivers for you so you don't have to do all that searching and downloading, but I think it's better to do it manually to make sure you're re-installing the latest drivers.
Another part of the preparation would be to make sure you have the installation files for all the programs you want to re-install handy as well.

If you want to tackle it at some stage you could post the details of your hardware here, someone will be able to tell you where to find what you need if you haven't been able to and probably also what you need but haven't realised you do, and then when you've got a day free to tackle it (I'd put one aside as re-installing everything can be time consuming) you can just go ahead and do it.

I'd also image the hard drive setup as soon as I had everything re-installed and set up. I use Norton Ghost to do it but there's free programs which will do the same job. That way when your PC gets messed up again down the track you can just restore the image and you're back where you were. I've got my method down to a fine art. I install Windows, update it, image it, install all my programs and image it again. On this PC it takes me about 5 minutes to image an entire setup (Windows and all the installed programs), and about two minutes to restore one.
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
)
mstuf
Posts: 419
(14 of 15)

Re: Problem Gone ? What to Do Now ??

Nov 5, 2009 12:30 AM
Thanks --

I did some reading tonight during dinner about Reinstalling XP -- my previous were with 9X versions - yes I typed XX not thinking how that could be confused.

Thanks for the checklist of things to prep and consider. I found a Tutorial on Google with a Step by Step Video of the process -- I'll watch that and look for items that my puzzle me .

Thanks
Reply
Name:
Email:
 
Tip: To create a link - type the desired text, highlight it with your mouse and click[Click for url tag]
Tags:
 
Page: of 2

New to eBay Boards? Try a visit to our Community Discussion Boards Help and Welcome Center .

Want to visit another board? You can view our Community Overview Page or select from these lists:

Community Help Boards:

eBay Tools Boards:

Category-Specific Boards:

General Discussion Boards:


Feedback Forum | Discussion Boards | Groups | Answer Center | Chat Rooms | Community Values

About eBay | Announcements | Security Center | Resolution Center | eBay Toolbar | Policies | Government Relations | Site Map | Help
Copyright © 1995-2009 eBay Inc. All Rights Reserved. Designated trademarks and brands are the property of their respective owners. Use of this Web site constitutes acceptance of the eBay User Agreement and Privacy Policy.
eBay official time
hosted by LiveWorld