Notices
The Basement Non-Honda/Acura discussion. Content should be tasteful and "primetime" safe.

antivirus people get in here

Thread Tools
 
Old Feb 26, 2010 | 05:57 PM
  #11  
whoaitslen2's Avatar
whoaitslen2
Thread Starter
hermit
 
Joined: Aug 2002
Posts: 6,421
Likes: 0
From: san diego
Default

Well my roommate's computer cutting in and out was a separate problem. Our wireless was acting up. Got that fixed.

I think I narrowed down my problem. Theres 2 iexplorer.exe running when I only have 1 open. In taskmgr Ill close the bigger iexplorer.exe and it will start itself back up. When I close the smaller one it stays closed. Doing some searching I found out its most likely a .dll code still lurking around after dodging many scans. Im no computer guru so I cant tell a legit .dll code from a fake one.

I would love to reformat but no disks. Laptop was already loaded with programs when bought.

Any other helpful tips? Im basically running different anitvirus programs, scanning, and praying it works, but no luck yet. At least this time I have an idea what the problem is.
Reply
Old Feb 26, 2010 | 06:06 PM
  #12  
spanky's Avatar
spanky
I go duffy on dem bitches
 
Joined: Mar 2001
Posts: 28,248
Likes: 0
From: Gonzales, Louisiana
Default

ive cleaned that up (in one form or another) on probably almost 100 computers.

go into safe mode w/ netowrking
run malwarebytes, remove everything
reboot back into safe mode w/ networking
run combofix
let combofix reboot your computer when its done, wait for the log, etc.
run cleanup!
reboot back into safe mode w/ networking, run cleanup again

Last edited by spanky; Feb 26, 2010 at 06:07 PM.
Reply
Old Feb 26, 2010 | 06:11 PM
  #13  
94civicEX's Avatar
94civicEX
I got worms.
 
Joined: Jul 2000
Posts: 32,238
Likes: 0
From: Utah
Default

I've had a lot of luck fully getting rid of infections using this forum - http://www.geekstogo.com/forum/Malwa...ide-t2852.html
__________________
99 Integra GSR
06 TSX

duck squad member #00003
Reply
Old Feb 26, 2010 | 09:14 PM
  #14  
BetterBob's Avatar
BetterBob
Nobama
 
Joined: Sep 2004
Posts: 6,961
Likes: 0
From: Sarasota, Florida
Default

My mediacenter is doing the exact same thing. I've been too busy to do anything about it though...

Maybe i'll fix it tonight.

Don't forget to pull all updates for malware, AVG, ect. beforehand.

Last edited by BetterBob; Feb 26, 2010 at 09:29 PM.
Reply
Old Feb 27, 2010 | 04:57 AM
  #15  
sids1045's Avatar
sids1045
dumber than a box of hair
 
Joined: May 2004
Posts: 518
Likes: 0
From: Stoneham MA
Default

Originally Posted by whoaitslen2
Thanks for the tips Ive done some major cleanup and scanning with AVG. But it still seems my internet connectivity is lacking. When I try to open a page most of the time it lags or just doesnt display. I have a feeling the virus screwed with commands or something before it was removed. Any other suggestions to get my internet connection running properly?
Make sure the crapware hasn't forced your Internet connection to use a proxy server. Tools > Internet Options > Connections tab > LAN Settings. If "Use a proxy server for your LAN" is checked, uncheck it, then close IE and re-open it.

A lot of the fake antivirus sites set the proxy server option.
Reply
Old Feb 27, 2010 | 09:44 AM
  #16  
whoaitslen2's Avatar
whoaitslen2
Thread Starter
hermit
 
Joined: Aug 2002
Posts: 6,421
Likes: 0
From: san diego
Default

Originally Posted by spanky
ive cleaned that up (in one form or another) on probably almost 100 computers.

go into safe mode w/ netowrking
run malwarebytes, remove everything
reboot back into safe mode w/ networking
run combofix
let combofix reboot your computer when its done, wait for the log, etc.
run cleanup!
reboot back into safe mode w/ networking, run cleanup again
Thanks just tried this. Looks like Im getting closer to finding the bug. Combo fix actually failed to remove a file. Here it is in the log...

c:\windows\system32\drivers\uustqai.sys . . . . failed to delete

I looked up its properties, it was created the exact time I got attacked. I try to request security info but it cant be displayed. I also cant delete it, rename it, relocate it... etc. "I always get "Cannot read from the source file or disk." Any ideas? Thanks again you guys have been nothing but helpful so far.

edit: just to add, I still have an extra iexplorer.exe running in task manager. probably due to uustqai.sys still active.

Last edited by whoaitslen2; Feb 27, 2010 at 09:46 AM.
Reply
Old Feb 27, 2010 | 10:12 AM
  #17  
BetterBob's Avatar
BetterBob
Nobama
 
Joined: Sep 2004
Posts: 6,961
Likes: 0
From: Sarasota, Florida
Default

Open malwarebytes, hit "more tools" and hit "run tool" under File Assassin.

See if that won't kill the file.
Reply
Old Feb 27, 2010 | 10:32 AM
  #18  
Fuse's Avatar
Fuse
Senior Member
 
Joined: Oct 2006
Posts: 1,335
Likes: 1
Default

I run avast also free and sybot also free.
Reply
Old Feb 27, 2010 | 12:02 PM
  #19  
BetterBob's Avatar
BetterBob
Nobama
 
Joined: Sep 2004
Posts: 6,961
Likes: 0
From: Sarasota, Florida
Default

I just ran malwarebytes, avg free, and ran msconfig.exe to clear out all but a couple start up items.

Seems to have fixed my problem.
Reply
Old Feb 28, 2010 | 02:26 PM
  #20  
94civicEX's Avatar
94civicEX
I got worms.
 
Joined: Jul 2000
Posts: 32,238
Likes: 0
From: Utah
Default

Originally Posted by 94civicEX
I've had a lot of luck fully getting rid of infections using this forum - http://www.geekstogo.com/forum/Malwa...ide-t2852.html
.
__________________
99 Integra GSR
06 TSX

duck squad member #00003
Reply



All times are GMT -8. The time now is 10:33 AM.