We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Possible virus - weird computer problem UPDATED with hijack results please help!

13

Comments

  • GunJack
    GunJack Posts: 11,879 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RIK, there were traces of TDSS rootkit and koobface in those logs, easy to miss in amongst all the mywebsearch carp....the good Doctor sounds like a good call ;)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    Ill put that down to my lack of sleep methinks :p
    :idea:
  • GunJack
    GunJack Posts: 11,879 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    aliEnRIK wrote: »
    Ill put that down to my lack of sleep methinks :p


    Ohhh yeahhhh....know that one :(
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • loulou123
    loulou123 Posts: 1,183 Forumite
    Thanks SO much guys, right....

    i ticked and fixed the things you mentioned in Hijack this, but then rescanned and their still there!

    SO i then downloaded the Dr Web thing and did the quick scan (after turning off virus scanner) and it found 3 trojans (came up in infected) which i tried to remove, but it said it couldnt so i quarantined them instead) here is the quick scan report (dont know if you need this)

    Scan statistics
    Scanned: 24180
    Infected: 3
    Modifications: 0
    Suspicious: 0
    Adware: 0
    Dialers: 0
    Jokes: 0
    Riskware: 0
    Hacktools: 0
    Cured: 0
    Deleted: 0
    Renamed: 0
    Moved: 3
    Ignored: 0
    Scan speed: 1 Kb/s
    Scan time: 0:30:00
    =============================================================================
    Total session statistics
    =============================================================================
    Scanned: 24180
    Infected: 3
    Modifications: 0
    Suspicious: 0
    Adware: 0
    Dialers: 0
    Jokes: 0
    Riskware: 0
    Hacktools: 0
    Cured: 0
    Deleted: 0
    Renamed: 0
    Moved: 3
    Ignored: 0
    Scan speed: 1 Kb/s
    Scan time: 0:30:30
    =============================================================================

    The 3 trojans it found are Trojan.PWS.Siggen.7946

    and Trojan.PWS.Siggen.8804

    and were all connected to the facemoods and SweetIM applications.

    I will run the full scan when i get home from work, but any tips on what i need to do next - am i safe now the 3 applications have been quarantined??
  • I hope your comp gets well soon!
  • GunJack
    GunJack Posts: 11,879 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    run ccleaner, both cleaner and registry parts

    http://www.filehippo.com/download_ccleaner/
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • loulou123
    loulou123 Posts: 1,183 Forumite
    Am running the full dr scan, but its been scanning for nearly 8 hours and is only about 3 quarters done!

    Has something gone wrong, or should it take so long?? It still seems to be scanning and hasn't obviously frozen or anything.

    Am writing this on phone, as I can't access anything whilst scan is preforming.

    Presuming the scan ever finishes do I delete everything it finds or cure or quaranteen it?
  • aliEnRIK
    aliEnRIK Posts: 17,741 Forumite
    Part of the Furniture Combo Breaker
    12 hours is an average for a full dr web scan

    Id quarantine everything personally
    :idea:
  • loulou123
    loulou123 Posts: 1,183 Forumite
    right full scan done, it found 11 'things'

    Scan statistics
    Scanned: 672888
    Infected: 9
    Modifications: 0
    Suspicious: 0
    Adware: 2
    Dialers: 0
    Jokes: 0
    Riskware: 0
    Hacktools: 0
    Cured: 0
    Deleted: 0
    Renamed: 0
    Moved: 7
    Ignored: 0
    Scan speed: 40 Kb/s
    Scan time: 20:44:36
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Documents and Settings\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Users\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Users\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Documents and Settings\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup - will be deleted after restart
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\ProgramData\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Users\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Users\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7db11111152015c0.bup
    C:\Users\All Users\McAfee\VirusScan\Quarantine\7db11111152015c0.bup - will be deleted after restart
    C:\ProgramData\McAfee\VirusScan\Quarantine\7db11111152015c0.bup - will be deleted after restart
    C:\Documents and Settings\All Users\Application Data\McAfee\VirusScan\Quarantine\7db11111152015c0.bup - will be deleted after restart
    =============================================================================
    Total session statistics
    =============================================================================
    Scanned: 673638
    Infected: 9
    Modifications: 0
    Suspicious: 0
    Adware: 2
    Dialers: 0
    Jokes: 0
    Riskware: 0
    Hacktools: 0
    Cured: 0
    Deleted: 4
    Renamed: 0
    Moved: 7
    Ignored: 0
    Scan speed: 43 Kb/s
    Scan time: 20:45:56
    =============================================================================

    I quaranted everything i could (4 of them would only give me delete as an option) what do i do with the quaranted things leave them where they are or delete?

    Am now going to download c cleaner, but just did another scan on anti malware and it was 100% ok, so presuming ccleaner is ok do you think im ok now???
  • loulou123
    loulou123 Posts: 1,183 Forumite
    HAve now installed and run ccleaner both the cleaner and registry parts and have fixed/deleted EVERYTHING it found (i did the back up thing too) and it found lots!

    So what next please you very kind people :D
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352K Banking & Borrowing
  • 253.5K Reduce Debt & Boost Income
  • 454.2K Spending & Discounts
  • 245K Work, Benefits & Business
  • 600.6K Mortgages, Homes & Bills
  • 177.4K Life & Family
  • 258.8K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16.2K Discuss & Feedback
  • 37.6K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.