We’d like to remind Forumites to please avoid political debate on the Forum.

This is to keep it a safe and useful space for MoneySaving discussions. Threads that are – or become – political in nature may be removed in line with the Forum’s rules. Thank you for your understanding.

📨 Have you signed up to the Forum's new Email Digest yet? Get a selection of trending threads sent straight to your inbox daily, weekly or monthly!

Win 7 Security 2011 $59.95 - Urgent Help Please

1235713

Comments

  • GunJack
    GunJack Posts: 11,888 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    ...and combofix is far more powerful than mse, and quicker too ;)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • RussJK
    RussJK Posts: 2,359 Forumite
    But - File Items 3 threats detected. Trojan.Agent/Gen-IExplorer (Fake)
    C:\USERS\CHRISTINE\APPDATA\LOCAL\TEMP\RARSFXD\NIRD\EXPLORER.EXE (I copied the details because I could not copy and paste them.)

    Were they similar to what Hitmanpro found? Combofix will wipe all temp folders in case there's other malware there.
  • GunJack
    GunJack Posts: 11,888 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    I've gotta say, when I'm removing carp from people's systems, I ALWAYS clear out the temp files first...you'd be surprised how much stuff only lives in them, and it's often a quick win in terms of removing infections....I'm honestly surprised people don't do this more as a matter of course....
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • RussJK
    RussJK Posts: 2,359 Forumite
    GunJack wrote: »
    I've gotta say, when I'm removing carp from people's systems, I ALWAYS clear out the temp files first...you'd be surprised how much stuff only lives in them, and it's often a quick win in terms of removing infections....I'm honestly surprised people don't do this more as a matter of course....

    Yeah agreed, used to be that and wipe all the restore points.

    Easy enough to wipe the temp folders in person, but I've been wanting a good failsafe & automated method to be able to direct people online to do, particularly for files resistant to deletion? Besides combofix.

    Ccleaner won't on the default settings ("only delete files in Windows Temp Folders older than 24 hours", and I don't think it does all user temp folders.
  • GunJack
    GunJack Posts: 11,888 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    RussJK wrote: »
    Yeah agreed, used to be that and wipe all the restore points.

    Easy enough to wipe the temp folders in person, but I've been wanting a good failsafe & automated method to be able to direct people to do online, particularly for files resistant to deletion? Besides combofix.

    Ccleaner won't on the default settings ("only delete files in Windows Temp Folders older than 24 hours", and doesn't do all user temp folders.

    What I tend to do is a combo of CCleaner, Glary Utilities, the inbuilt windows disk cleanup, and just for good measure, each installed browser's cache. A little intense maybe, but there's not much left hanging around after doing all that ;)
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • closed
    closed Posts: 10,886 Forumite
    if an infection is running from temp, standard cleanup utilities won't remove it unless set to remove at boot, and if it's not running, it's harmless - apart from that ccleaner does a good a job as any.
    !!
    > . !!!! ----> .
  • RussJK
    RussJK Posts: 2,359 Forumite
    closed wrote: »
    if an infection is running from temp, standard cleanup utilities won't remove it unless set to remove at boot, and if it's not running, it's harmless - apart from that ccleaner does a good a job as any.

    Well unless you're running in safe mode, then some of it might be temporarily inactive.
  • GunJack
    GunJack Posts: 11,888 Forumite
    Part of the Furniture 10,000 Posts Name Dropper Photogenic
    closed wrote: »
    if an infection is running from temp, standard cleanup utilities won't remove it unless set to remove at boot, and if it's not running, it's harmless - apart from that ccleaner does a good a job as any.

    good point :) Must admit, when I clear out I do tend to run RKill first as much as poss, just to help out.
    ......Gettin' There, Wherever There is......

    I have a dodgy "i" key, so ignore spelling errors due to "i" issues, ...I blame Apple :D
  • Hello everyohne - I've just finished running Microsoft Security Essentials Quick Scan and thankfully there were no threats. I'm now going to follow your welcome advice above (belt and braces) and empty Temporary Internet Folders followed by the combofix - I'll report back later. Thank you again.

    Crimson
  • RussJK
    RussJK Posts: 2,359 Forumite
    edited 8 May 2011 at 11:12PM
    The other side of the coin is that if malware is running from temp files, then you want it gone whether or not the security tools recognise it.

    I should have known Oldtimer would already have a tool for this.

    TFC - Temp File Cleaner by OldTimer :
    http://www.geekstogo.com/forum/files/file/187-tfc-temp-file-cleaner-by-oldtimer/

    It removes from all the temp folders including the Java cache and browser cache, and deletes on bootup what it can't delete. Just a simple, straightforward tool that just does what it's meant to. Will have to test it out, really glad to find it as it fits exactly what I was after.

    Personally I would do a pass with Malwarebytes first based on the advice of the developers as MBAM seems to rely on malware running normally as part of its heuristics (at least that's why they say not to run it in safe mode unless you have to, and the excuse they give for why they don't have a portable or bootable version of MBAM). Afterwards then try fracturing the malware with rkill and TFC in case it's still hiding components.
This discussion has been closed.
Meet your Ambassadors

🚀 Getting Started

Hi new member!

Our Getting Started Guide will help you get the most out of the Forum

Categories

  • All Categories
  • 352.2K Banking & Borrowing
  • 253.6K Reduce Debt & Boost Income
  • 454.3K Spending & Discounts
  • 245.2K Work, Benefits & Business
  • 600.9K Mortgages, Homes & Bills
  • 177.5K Life & Family
  • 259K Travel & Transport
  • 1.5M Hobbies & Leisure
  • 16K Discuss & Feedback
  • 37.7K Read-Only Boards

Is this how you want to be seen?

We see you are using a default avatar. It takes only a few seconds to pick a picture.