PDA

View Full Version : got virus, now what


Aerozord
07-24-2010, 11:29 PM
AVG didn't pick it up, and I did clean out internet history and everything. not sure what else I can do short of wiping my system

Grimpond
07-24-2010, 11:38 PM
Try Malware Bytes, Spybot - Search & Destory, and SUPERAntiSpyware Free Edition.

That's what I use at least

synkr0nized
07-24-2010, 11:41 PM
See Sticky (http://www.nuklearforums.com/showthread.php?t=37503)

Try some other scanners, use a LiveCD scanner, and/or make use of another system to clean this one (though, of course, depending on the virus you will have to take the appropriate precautions to keep the latter system from also getting infected [e.g. use a Linux machine]).

More information on what you have would be helpful.

Aerozord
07-25-2010, 12:43 AM
well I feel like an idiot, I wasn't thinking and clicked one of those IM spam links. If that helps narrow down what exactly cleans it out.

in any case I will do as the sticky suggested tomorrow

Nikose Tyris
07-25-2010, 06:52 AM
Uninstall Chat program
Clear history and all cookies
Change password on facebook
Change password on Email addresses/chats
Re-install Chat programs

Continue as normal.

Aerozord
07-25-2010, 01:31 PM
chat program is windows live messenger, which doesn't seem to have an uninstall option. Nor can I find it in add/remove program list

Nikose Tyris
07-25-2010, 03:30 PM
It's there. Windows Live Essentials. I talked Joshelplex through this like yesterday.

Aerozord
07-26-2010, 03:08 PM
ok not sure which bit of advice helped, I basically did them all, but it seems fine now. I'll post again if anything shows up. Thanks everyone

Seil
07-26-2010, 05:11 PM
Out of curiostity, did you know what it was you got infected with?

Aerozord
07-26-2010, 05:22 PM
well I'm not great at virus lexicon, but this is what malwarebytes told me


Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\Curre ntVersion\Run\java developer script browse (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run\java developer script browse (Trojan.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentV ersion\Run\java developer script browse (Trojan.Agent) -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
C:\Documents and Settings\Nick\Local Settings\Temp\11.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\Documents and Settings\Nick\Local Settings\Temp\5.tmp (Backdoor.Bot) -> Quarantined and deleted successfully.
C:\WINDOWS\jusched.exe (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS\wintybrd.png (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\wintybrdf.jpg (Malware.Trace) -> Quarantined and deleted successfully.