Jump to content


Photo
- - - - -

New Thread infected


  • This topic is locked This topic is locked
41 replies to this topic

#21 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 20 April 2012 - 03:41 PM

OK.
Lets see what happens
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#22 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 21 April 2012 - 07:53 AM

Also do this

Check the settings.

1. Click Start, click Control Panel, and then click User Accounts.
2. Click the Advanced tab.
3. In the "Secure logon" section, select the "Require users to press Ctrl+Alt+Delete" check box.

Make sure the guest account is disabled and you have a user login and passowrd.


Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#23 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 24 April 2012 - 01:27 PM

Did that work?
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#24 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 24 April 2012 - 02:35 PM

i have applied the changes but have not really had time to verify if the issue is still happening as it is finals week here. I will try to look when i have time and update with further info.

#25 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 24 April 2012 - 05:08 PM

Finals come first Posted Image
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#26 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 04:38 PM

Was just able to confirm the problem is still happening.

#27 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 05:24 PM

Did you create a password for the administrator account?
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#28 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 07:05 PM

Yes i did add a password as well as activate the ctrl+alt+del option.

#29 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 07:07 PM

I've had a couple more just like yours and doing that cured those.
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#30 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 07:10 PM

Did you reinstall the firewall?
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#31 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 07:26 PM

no i have not re-installed the fire wall. I was using comodo but am not set on that if there is a more preferable one.

#32 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 07:28 PM

I'd try Windows 7 firewall.

Just go into the security settings and activate it.
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#33 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 07:30 PM

Okay i will activate it now.

#34 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 07:31 PM

We'll see if that does it.
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#35 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 07:54 PM

it turns out it was activated already.

#36 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 30 April 2012 - 07:58 PM

OK.
Lets give this a try.

http://www.eset.eu/online-scanner
Go here to run an online scannner from ESET.
Click the green ESET Online Scanner button.
Read the End User License Agreement and check the box: YES, I accept the Terms of Use.
Click on the Start button next to it.
You may receive an alert on the address bar that "This site might require the following ActiveX control...Click here to install...". Click on that alert and then click Insall ActiveX component.
A new window will appear asking "Do you want to install this software?"".
Answer Yes to download and install the ActiveX controls that allows the scan to run.
Click Start.
Make sure that the option "Remove found threats" is Unchecked
Click Scan to begin.
If offered the option to get information or buy software. Just close the window.
Wait for the scan to finish
Use notepad to open the logfile located at C:\Program Files\EsetOnlineScanner\log.txt
Copy and paste that log as a reply to this topic.
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#37 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 08:47 PM

This popped up during the scan from my antivirus. The two options given are to delete or no action. 4/30/2012 9:42:06 PM Real-time file system protection file C:\Users\Kenny\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\CH73I8RI\mop[1].htm JS/Exploit.Shellcode.A.gen trojan cleaned by deleting - quarantined Kenny-PC\Kenny Event occurred during an attempt to access the file by the application: C:\Program Files (x86)\ESET\ESET Online Scanner\OnlineCmdLineScanner.exe.

However it looks like this may be from the online scanner so i did not answer whether to delete or not. The scan is almost complete i will update with the log soon.

#38 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 30 April 2012 - 09:53 PM

Scan results

ESETSmartInstaller@High as CAB hook log:
OnlineScanner64.ocx - registred OK
OnlineScanner.ocx - registred OK

#39 LDTate

LDTate

    Forum Deity

  • Moderators
  • PipPipPipPipPipPip
  • 20,228 posts
  • Gender:Male
  • Location:Missouri, USA

Posted 01 May 2012 - 06:17 AM

We can keep trying.

Please download JavaRa to your desktop and unzip it to its own folder
  • Run JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista), pick the language of your choice and click Select. Then click Remove Older Versions.
  • Accept any prompts.
  • Open JavaRa.exe (double-click for XP/right-click and Run as Administrator for Vista) again and select Search For Updates.
  • Select Update Using Sun Java's Website then click Search and click on the Open Webpage button. Download and install the latest Java Runtime Environment (JRE) version for your computer.

Next:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Lets see what that does.
Larry Tate
Consumer Support Specialist

Posted Image

Follow us: Twitter, Become a fan: Facebook

#40 kl3zero

kl3zero

    New Member

  • Members
  • Pip
  • 27 posts

Posted 01 May 2012 - 11:49 AM

Just finished doing the 2 steps. Upon reboot the issue started happening within 5 minutes.




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users