Author Topic: my computer is infected...  (Read 1295 times)

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computer is infected...
« Reply #20 on: April 11, 2008, 11:28:20 PM »
Yes, you can enter Avast virus chest and remove everthing in there

In addition, you should also do the following
Go to START>>All Programs>>Accessories>>System Tools>>System Restore
Select>>Create a New restore point
Give it a name, any name,
 and click Create
Windows will prompt when it was created successfully
When that's done

Go to START>>RUN>>type the following
cleanmgr
Hit OK
Let if finish calculating

Select the More Options tab
and click Cleanup.. under 'System Restore'
This will clear all later restore points except for the one you just made

Ok the prompts, it may take a few seconds to remove old restore points
Ok again after it's ready and let it finish cleaning


Go to START>>RUN>>copy then paste the next entry in bold

ComboFix /u
Then hit OK
This will uninstall combofix

You should remove all older versions of Sun Java, keep only the latest
Access your Add/remove programs and with all browser windows closed Remove

J2SE Runtime Environment 5.0 Update 2
Javaâ„¢ 6 Update 2
Javaâ„¢ 6 Update 3
Javaâ„¢ SE Runtime Environment 6 Update 1


Leave ONLY
Javaâ„¢ 6 Update 5 installed

You can also open Malwarebytes Anti-malware and open the Quarantine section and removal all
Optionally, Uninstall Malwarebytes from add/remove
Or leave it installed and occassionally update and run a scan

Go to START>>RUN>>type the following
cleanmgr
Hit OK
Let if finish calculating

Select the More Options tab
and click Cleanup.. under 'System Restore'
This will clear all later restore points except for the one you just made

Ok the prompts, it may take a few seconds to remove old restore points
Ok again after it's ready and let it finish cleaning

OTMoveIt2
  • Double-click OTMoveIt2.exe to run it.
  • Click the Cleanup! button
    A list will be downloaded>>Allow it Internet access if prompted by your Firewall
    Don't change anything in this list
  • Select Yes at the prompt
    Wait for the confirmation box to open to reboot the computer
    Don't mouseclick during the wait as you may cause the tool to stall
  • Select Yes to reboot Now
NOTE: This procedure will also delete OTMoveit.exe from desktop

I suggest that you add SpywareBlaster to your protection software
SpywareBlaster  by JavaCool  
    *Will block bad ActiveX Controls
    *Block Malevolent cookies in Internet Explorer and Firefox
    *Restrict actions of potentially dangerous sites in Internet Explorer
After installation, Check for updates
After updating, select "Protection Status" on the Left
Then select "Enable all Protection"
"Check for updates every couple of weeks"
after every update just simply click the "enable protection on all unprotected items"

You can go ahead and reinstall Spybot 1.5.2.20 from
HERE
Since you had trouble with the TeaTimer, you may want to uncheck that option when installing
But keep all other defaults
In addition, utilize the Immunzation of Spybot
After every update, click on IMMUNIZATION>>Immunization at the top green cross
To that after every update
Occassionally, after updating, Check for problems and remove everything in RED

Hope that helps  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />
« Last Edit: April 11, 2008, 11:30:15 PM by guestolo »

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline mchll9898

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
my computer is infected...
« Reply #21 on: April 12, 2008, 10:25:09 PM »
oh my goodness!  I caught the icon popping up again!  I wish I knew what it was...

And OTMoveit isn't working for me for some reason, even though I leave it alone and don't touch my computer, it kinda just freezes and does nothing.

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computer is infected...
« Reply #22 on: April 12, 2008, 10:51:26 PM »
So when it pops up, can you right click on it and select ABOUT and see what it's related too
Are you checking your email at the same time this is happening?

Can you ensure you close down what you don't need running in Task Manager
and see what it may be related too?

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline mchll9898

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
my computer is infected...
« Reply #23 on: April 13, 2008, 12:39:20 PM »
I kept outlook express open and watched and it makes the icon pop up when outlook sends/receives (I have it set to do it automatically every couple minutes).  It never did that before and I can't remember doing an update or anything.  But anyways, now that I know what it is, I think I'm all set.  

But OTMoveit still isn't working...

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computer is infected...
« Reply #24 on: April 13, 2008, 06:07:22 PM »
Going back to your screenshot you posted

The icons in your system tray
The 2 set by Avast are the round icons with the

i and the a
If you don't want the i visible
Just right click on it and merge it with the main icon

Ensure you have registered your free copy of Avast
Which includes copy>>pasting the license key emailed to you into Avast
When your version expires, in about 14 months, no need to reinstall
Just reregister, and copy>paste new license key emailed

Can you do me a favor
Can you delete your copy of OTMoveit2.exe on desktop
Then RIGHT CLICK On the AVAST (a) icon by the clock and
Temporarily STOP ON ACCESS PROTECTIONS
OK the prompt

Then redo this step
download the [color=\"red\"]OTMoveIt2 by OldTimer[/color][/url].
  • Save it to your desktop.
  • Double-click OTMoveIt2.exe to run it.
  • Click the Cleanup! button
    A list will be downloaded>>Allow it Internet access if prompted by your Firewall
    Don't change anything in this list
  • Select Yes at the prompt
    Wait for the confirmation box to open to reboot the computer
    Don't mouseclick during the wait as you may cause the tool to stall
  • Select Yes to reboot Now
NOTE: This procedure will also delete OTMoveit.exe from desktop

If it still won't work, don't worry, we'll manually delete folders/files
If you didn't get a prompt to reboot
and/or OTMoveIt2 still won't run the Cleanup
Go back and START ON ACCESS PROTECTIONS
Note>The protections should reenable after a reboot, but double check that they're running

Quote
I kept outlook express open and watched and it makes the icon pop up when outlook sends/receives (I have it set to do it automatically every couple minutes). It never did that before and I can't remember doing an update or anything. But anyways, now that I know what it is, I think I'm all set.

Silly me, it makes sense now why you see that Icon
It's probably Avast Internet email scanner
If you DOUBLE CLICK on the Avast a icon by the clock
The On-Access Scanner window opens
Click on MORE DETAILS
Under the Installed Scanners list
Highlight "Internet Mail"
Then select "Customize" on the right hand side
Click on the ADVANCED tab
You should see a selection "Show tray icon when scanning mail"
You can leave it selected or unselected, your option

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline mchll9898

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
my computer is infected...
« Reply #25 on: April 15, 2008, 10:06:25 PM »
i did what you said, but OTMoveit still isn't working.  So what files should I remove?

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computer is infected...
« Reply #26 on: April 15, 2008, 11:08:18 PM »
Thanks for retrying the automatic removal with OTMoveit2

From desktop, manually delete OTMoveIt2.exe
Also remove
ComboFix.exe

Find and delete these folders
C:\Qoobox
C:\_OTMoveIt

If you haven't done the remainder of the instructions in Post #21, do so now

If everything is running ok, let me know, I'll lock this topic

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here


Offline mchll9898

  • Newbie
  • *
  • Posts: 17
  • Karma: +0/-0
    • View Profile
my computer is infected...
« Reply #27 on: April 16, 2008, 08:12:09 AM »
I can't find either of those files... maybe OTmoveit worked and just didn't show me the results?

Anyways, thanks so much for all your help.  My computer seems to be virus free.  My shared folder isn't flooded with thousands of zip files.  I owe it all to you.  Thanks! http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Offline guestolo

  • Site Donator
  • Administrator
  • Hero Member
  • *****
  • Posts: 16034
  • Karma: +1/-0
    • View Profile
    • http://
my computer is infected...
« Reply #28 on: April 16, 2008, 08:18:54 AM »
Your welcome
I'll lock this topic then as your problems appear resolved
Take care mchll9898  http://images.thetechguide.com/forum/public/style_emoticons/<#EMO_DIR#>/smile.gif\' class=\'bbc_emoticon\' alt=\':)\' />

Do you want to post your own logs from FRST?

Follow the instructions posted http://www.thetechguide.com/forum/index.php/topic/22942-please-read-how-to-post-logs-from-frst/\'>Click Here