being attacked by 208.73.210.29; MBAB blocking outbound access every 5-10 minutes
#81
Posted 01 May 2012 - 12:42 PM
Based on yesterday's experience (I did not get the pop ups at all during the day), it may be tomorrow morning before I see anything again. I will go radio silent unless I hear from you until tomorrow morning. I will let you know what happens after 6:09.
Thanks again for hanging in there with me.
#82
Posted 01 May 2012 - 12:54 PM
A friend asked if I knew the name of the virus I got infected with. Does this thing have a name?
#83
Posted 01 May 2012 - 01:32 PM
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#84
Posted 01 May 2012 - 02:33 PM
#85
Posted 01 May 2012 - 02:34 PM
#86
Posted 01 May 2012 - 03:31 PM
does the malware, virus, whatever have a purpose?
It certain does, most likely malicious.
Oversee.net <---------has a real bad reputation
http://oversee.net/privacy-policy <---privacy policy
http://hosts-file.net/?s=oversee.net <---review of the site
Softlayer Technologies <---seems OK but is still blocked by MVPS HOSTS
http://www.softlayer.com/ <---site
http://www.hostrevie...er-technologies <---review of site
MVPS HOSTS file:
http://winhelp2002.mvps.org/hosts.txt <-----what the MVPS host file blocks
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#87
Posted 01 May 2012 - 03:43 PM
#88
Posted 01 May 2012 - 03:54 PM
Have you ever cleared out all your cookies??
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#89
Posted 01 May 2012 - 04:12 PM
#90
Posted 01 May 2012 - 04:17 PM
Double-click ATF Cleaner.exe to open it
http://www.atribune..../click.php?id=1
Under Main choose:
Windows Temp
Current User Temp
All Users Temp
Cookies
Temporary Internet Files
Prefetch
Java Cache
*The other boxes are optional*
Then click the Empty Selected button.
If you use Firefox:
Click Firefox at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
If you use Opera:
Click Opera at the top and choose: Select All
Click the Empty Selected button.
NOTE: If you would like to keep your saved passwords, please click NO at the prompt.
Click Exit on the Main menu to close the program.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#91
Posted 01 May 2012 - 04:22 PM
#92
Posted 01 May 2012 - 04:44 PM
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#93
Posted 01 May 2012 - 05:06 PM
#94
Posted 01 May 2012 - 05:21 PM
http://www.adtrader.com
Should I expect any negative impact from MVPS -- anything to be on the lookout for?
No, this is a good program to have on the system, it won't allow you to go to a bad site.
Read all about it on this page:
http://winhelp2002.mvps.org/hosts.htm
We can always return to the original host file....it's still on the system.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#95
Posted 01 May 2012 - 05:28 PM
So I assume it's safe to put on all computers used by the kids?
#96
Posted 01 May 2012 - 05:30 PM
You have to update it once in a while though.
MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#97
Posted 04 May 2012 - 07:56 AM
Do you still need help or can I close this post, MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
#98
Posted 04 May 2012 - 10:08 AM
Thank you very much for your help.
Can you give me a suggestion for Paypal?
#99
Posted 04 May 2012 - 10:13 AM
I did not seen any pop-ups on Tues or Wed after we changed the hosts file, and have not seen any today. I have also checked the MBAM logs and don't see any blocked IP addresses since the Tues morning incident, again, before we changed the hosts file.
OK, that's good news
Can you give me a suggestion for Paypal?
That's up to you
---------------------------------------
I see your a Honorary Members now!!
-----------------------------------------------------
Some clean up to do............
Please Uninstall ComboFix:
Press the Windows logo key + R to bring up the "run box"
Copy and paste next command in the field:
ComboFix /uninstall
Make sure there's a space between Combofix and /

Then hit enter.
This will uninstall Combofix, delete its related folders and files, hide file extensions, hide the system/hidden files and clears System Restore cache and create new Restore point
---------------------------------
Run OTL and hit the CleanUp button. (This will cleanup the tools and logs used including itself)
Any other programs or logs you can manually delete.
-------------------------------
Any questions...please post back.
If you think I've helped you, please leave a comment > click on my avatar picture > click Profile Feed.
Take a look at My Preventive Maintenance to avoid being infected again.
Good Luck and Thanks for using the forum, MrC
Malware Removal Expert
I volunteer my free time to help you, if you would like to donate to show your appreciation, it will be much appreciated.
Thanks MrC & crew
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users



This topic is locked










