Malware/Spyware question

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • rago88
    Digital Video Expert
    Digital Video Expert
    • Aug 2005
    • 566

    Malware/Spyware question

    Don;t know if this is the right forum to post but members here are so knowledgable and have the right answers pretty quick..

    I use malwareytes.exe which has gotten rid of lot's of video eggs, maleware trojans etc and just recently that " you have a security problem" taskbar popup that I could not get rid of till useing free Malwarebytes.exe.
    Anyway, Webroot spyware and the above don't seem to get along when I update as each one finds the other to be a virus.
    Throw in Avast ant-virus and it's a 3 ring circus.
    Is there a difference between spyware and adware as I would like to know if I still need to have webroot spyware enabled..
    they are both good programs but Malware bytes found a lot of stuff that has been laying dormant for long time on my PC and many it found appeared to be spyware that I think webroot spyware should have caught...
    Last edited by rago88; 30 Nov 2008, 04:38 AM.
  • soup
    Just Trying To Help
    • Nov 2005
    • 7524

    #2
    All I use on my XP64 side is Comodo for 2-way firewall & Avira AntiVir (free) with the occasional scan with Malwarebytes, which I keep updated or Windows Live One Care.

    Comment

    • rago88
      Digital Video Expert
      Digital Video Expert
      • Aug 2005
      • 566

      #3
      Avast virus and Malware are both free here.
      Webroot is the pay software...

      Think I will can Webroot...
      seems like it and Malware are going after the same stuff..

      Comment

      • Chewy
        Super Moderator
        • Nov 2003
        • 18971

        #4
        Post some of the malwarebyte's logs

        there's some real nasty stuff going around the last few weeks

        Comment

        • rago88
          Digital Video Expert
          Digital Video Expert
          • Aug 2005
          • 566

          #5
          [I][B]here's a partial list......... \

          Malwarebytes' Anti-Malware 1.30
          Database version: 1434
          Windows 5.1.2600 Service Pack 3
          11/29/2008 12:32:39 PM
          mbam-log-2008-11-29 (12-32-39).txt
          Scan type: Quick Scan
          Objects scanned: 53272
          Time elapsed: 4 minute(s), 31 second(s)
          Memory Processes Infected: 2
          Memory Modules Infected: 0
          Registry Keys Infected: 42
          Registry Values Infected: 3
          Registry Data Items Infected: 0
          Folders Infected: 14
          Files Infected: 293
          Memory Processes Infected:
          C:\Documents and Settings\tony\Local Settings\Temp\~tmpc.exe (Trojan.FakeAlert) -> Unloaded process successfully.
          C:\Documents and Settings\tony\Local Settings\Temp\~tmpb.exe (Trojan.FakeAlert) -> Unloaded process successfully.
          Memory Modules Infected:
          (No malicious items detected)
          Registry Keys Infected:
          deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461 (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\gid326 (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\gid326\cid1 094 (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\gid326\cid1 094\AOL1 (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\gid326\cid1 094\AOL1\images (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\im ages (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\resources\VideoEgg\me ssages (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Updater (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Updater\2817 (Adware.VideoEgg) -> Quarantined and deleted successfully.
          Files Infected:
          C:\Documents and Settings\tony\Local Settings\Temp\~tmpc.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Local Settings\Temp\~tmpb.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          C:\WINDOWS\Downloaded Program Files\popcaploader.dll (Adware.PopCap) -> Quarantined and deleted successfully.
          C:\Program Files\VideoEgg\Loader\2817\npvideoegg-loader.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\WINDOWS\system32\msxml71.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
          C:\Documents and Settings\All Users\Application Data\VideoEgg\user.dat (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\publisher.ver (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\avcodec.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\crashRpt.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\FLVEncoder.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\lame_enc.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\LevelMeter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\libcurlve.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\libpng.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\npvideoegg-publisher.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\remoteblacklist (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\report.log (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\VideoEgg_FLVWriter.ax (Adware.VideoEgg) -> Quarantined and deleted successfully.
          C:\Documents and Settings\tony\Application Data\VideoEgg\Publisher\3461\zlib.dll (Adware.VideoEgg) -> Quarantined and deleted successfully.
          Last edited by rago88; 30 Nov 2008, 09:57 AM.

          Comment

          • blutach
            Not a god of digital video
            • Oct 2004
            • 24627

            #6
            The infected files are (thankfully) temp files. The other issues appear to be in your appdata folder (where, usually you do not find dlls).

            Just let it repair (as you have done) and you'll be right. Run another test (full scan) and then reboot. Then do another quickie.

            Regards
            Last edited by blutach; 30 Nov 2008, 10:40 AM.
            Les

            Essential progs - [PgcEdit] [VobBlanker] [MenuShrink] [IfoEdit] [Muxman] [DVD Remake Pro] [DVD Rebuilder] [BeSweet] [Media Player Classic] [DVDSubEdit] [ImgBurn]

            Media and Burning - [Golden Rules of Burning] [Media quality] [Fix your DMA] [Update your Firmware] [What's my Media ID Code?] [How to test your disc]
            [What's bitsetting?] [Burn dual layer disks safely] [Why not to burn with Ner0] [Interpret Ner0's burn errors] [Got bad playback?] [Burner/Media compatibility]

            Cool Techniques - [2COOL's guides] [Clean your DVD] [Join a flipper] [Split into 2 DVDs] [Save heaps of Mb] [How to mock strip] [Cool Insert Clips]

            Real useful info - [FAQ INDEX] [Compression explained] [Logical Remapping of Enabled Streams] [DVD-Replica] [Fantastic info on DVDs]


            You should only use genuine Verbatim or Taiyo Yuden media. Many thanks to www.pcx.com.au for their supply and great service.

            Explore the sites and the programs - there's a gold mine of information in them

            Don't forget to play the Digital Digest Quiz!!! (Click here)

            Comment

            • rago88
              Digital Video Expert
              Digital Video Expert
              • Aug 2005
              • 566

              #7
              That's what I did Blutach.
              Ran the 1st quick scan, dumped the bad files then ran a 35 minute full scan, then re-booted..

              last but not least, the original question was, do I still need webroot spyware along with Avast and malwarebytes.
              I really don't think I do myself.

              Comment

              • Chewy
                Super Moderator
                • Nov 2003
                • 18971

                #8
                Avast has a suite of components, av, firewall, etc so I would just use MBAM to supplement avast

                Just to be safe I would run a good safemode scanner

                Antivirus Xp? - posted in Am I infected? What do I do?: My computer was recently infected with antivirus xp. I seemed to have uninstalled the program itself, but i think whatever came with it is still there. I've tried running norton, adaware and avg, and they've all crashed or are denied access to certain folders. When i try to look in the registry or go looking around in windows explorer, it also closes with no error message. So i'm not entirely sure what I should be posti...

                Comment

                • doctorhardware
                  Lord of Digital Video
                  Lord of Digital Video
                  • Dec 2006
                  • 1907

                  #9
                  Also turn off system restore and when you are done and have no more problems turn system and create a new restore point.
                  Star Baby Girl, Born March,1997 Died June 30th 2007 6:35 PM.

                  Comment

                  • rago88
                    Digital Video Expert
                    Digital Video Expert
                    • Aug 2005
                    • 566

                    #10
                    good tips... thanx............

                    Comment

                    • blutach
                      Not a god of digital video
                      • Oct 2004
                      • 24627

                      #11
                      Yeah -0 turning off System Restore gets rid of all the restore points (including the malware in the saved system volume information).

                      Regards
                      Les

                      Essential progs - [PgcEdit] [VobBlanker] [MenuShrink] [IfoEdit] [Muxman] [DVD Remake Pro] [DVD Rebuilder] [BeSweet] [Media Player Classic] [DVDSubEdit] [ImgBurn]

                      Media and Burning - [Golden Rules of Burning] [Media quality] [Fix your DMA] [Update your Firmware] [What's my Media ID Code?] [How to test your disc]
                      [What's bitsetting?] [Burn dual layer disks safely] [Why not to burn with Ner0] [Interpret Ner0's burn errors] [Got bad playback?] [Burner/Media compatibility]

                      Cool Techniques - [2COOL's guides] [Clean your DVD] [Join a flipper] [Split into 2 DVDs] [Save heaps of Mb] [How to mock strip] [Cool Insert Clips]

                      Real useful info - [FAQ INDEX] [Compression explained] [Logical Remapping of Enabled Streams] [DVD-Replica] [Fantastic info on DVDs]


                      You should only use genuine Verbatim or Taiyo Yuden media. Many thanks to www.pcx.com.au for their supply and great service.

                      Explore the sites and the programs - there's a gold mine of information in them

                      Don't forget to play the Digital Digest Quiz!!! (Click here)

                      Comment

                      • Chewy
                        Super Moderator
                        • Nov 2003
                        • 18971

                        #12
                        As a general rule, the safest approach, is create a new restore point when you think the infection is all gone, then delete all but the newest one

                        tricky

                        disk cleanup more options

                        Comment

                        • rago88
                          Digital Video Expert
                          Digital Video Expert
                          • Aug 2005
                          • 566

                          #13
                          did that...
                          turned off Restore which deleted all past backups then made a restore point as of today...

                          Comment

                          Working...