Page 12 of 13 FirstFirst ... 210111213 LastLast
Results 111 to 120 of 128

Thread: [ROOTKIT INFECTION] PUP.BitMiner: kwrd.dll

Hybrid View

  1. #1
    ESET came up clean.

  2. #2
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079


    Sorry, got a bit overwhelmed.

    Ok, now for the security! First of all try to uninstall Combofix using that uninstall instruction I gave earlier. If that doesn't work the download OTC

    again and use it. But try the "normal" way first. Then I will give you a new anti-virus program to install...FREE one, excellent too.

  3. #3
    Uninstalled successfully via the "normal" way.

  4. #4
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Ok, here you go. This is Avira 2012 Free, an excellent Free anti-virus. Scores in the top three consistently in independent testing of both free and paid av programs. I have used it for years, literally and love it. Works great on Windows 7 too.

    Go to this page to download. Download the top choice which is the .exe file save it to the desktop for "easy finding"
    http://www.avira.com/en/support-down...free-antivirus

    Here are the install instructions, WITH printscreens to lead the way.
    To begin, double click the executable file to start installation. Vista and Windows 7 users must run this executable as Admininistrator.

    Before installation the installer will scan your system for other security programs installed. Avira Free AntiVirus 2012 may warn you of POSSIBLE incompatible security software on your system like Emsisoft AntiMalware, some 3rd party Firewalls, especially Zone Alarm. It is just a warning of POSSIBLE conflicts and you do not need to uninstall these software programs. Just install Avira Free AV and everything is OK. I was warned about SpyBot and SpywareBlaster, I IGNORED the warning, I still have the programs and they ARE working fine. The warning is of POSSIBLE conflicts, not absolutes. I say again, you DO NOT have to uninstall the programs you may receive a warning about.

    Next steps are:
    One of the first screens you will see is Attachment #1. Choose Installation Type choose CUSTOM INSTALL as shown then click Next.
    One of the next screens you will see is Attachment #2.
    The screen is titled Web Protection with Avira Search Free Tool Bar for your browser. You DO NOT want either one of these. There are two check boxes there, DO NOT Put any check marks in them, just click Next.
    The next screens are pretty self explanatory.

    Attachment #3 shows Install Components. Check marks are all ready in place as these are the Default choices. Just click Next.

    Attachment #4 is Advanced Heuristic Analysis and Detection. Default is Medium. Just click Next. After that installation will proceed to the end, showing you various screens.

    When complete the program should update to latest definitions and then do a short scan. Next post I will have attachments show how to schedule scans and an additional update.
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	Avira 1.jpg 
Views:	5 
Size:	48.6 KB 
ID:	2077   Click image for larger version. 

Name:	Avira 2.jpg 
Views:	3 
Size:	72.3 KB 
ID:	2078   Click image for larger version. 

Name:	Avira 3.jpg 
Views:	3 
Size:	53.2 KB 
ID:	2079   Click image for larger version. 

Name:	Avira 4.jpg 
Views:	3 
Size:	68.5 KB 
ID:	2080  

  5. #5
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Here is how to schedule weekly scan and an additional daily update. The program has one auto update built in which is set by the program and cannot be removed. It will update at approximately the time the program was first installed and updated. I set another one for myself for approx. 12 hours later, but you can do it anytime you wish. Avira releases multiple updates daily and that is why I do the second one. They usually don't have any on the weekends, the company and server are located in Germany and adding one at a different time of day will take their time zone difference into account also. They are 6 hours ahead of EST.
    The free version also will show one LARGE pop a day urging users to purchase the paid version, this is just the "price you pay" for using the free version. Just "x" out of that pop up is all that is needed. It pops up when the one built in update takes place.
    Here are the print screens for using the scheduler I will have to do this in two posts because there is a 5 attachment limit. Pretty self explanatory but if you have questions I will be happy to answer any you may have.
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	Avira Scheduler.jpg 
Views:	4 
Size:	76.1 KB 
ID:	2087   Click image for larger version. 

Name:	Avira Insert New Job.jpg 
Views:	5 
Size:	64.9 KB 
ID:	2088   Click image for larger version. 

Name:	Avira system scan 1.jpg 
Views:	3 
Size:	57.8 KB 
ID:	2089   Click image for larger version. 

Name:	Avira system scan 2.jpg 
Views:	3 
Size:	46.3 KB 
ID:	2090   Click image for larger version. 

Name:	Avira system scan 3.jpg 
Views:	4 
Size:	43.8 KB 
ID:	2091  


  6. #6
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Here are the rest and after these I have a couple more suggestions for you and at least one more FREE security program. Do this install and set up and then come back and we can finish up.
    Attached Thumbnails Attached Thumbnails Click image for larger version. 

Name:	Avira system scan 4.jpg 
Views:	3 
Size:	55.8 KB 
ID:	2092   Click image for larger version. 

Name:	Avira system scan 5.jpg 
Views:	2 
Size:	42.8 KB 
ID:	2093   Click image for larger version. 

Name:	Avira Update 2.jpg 
Views:	2 
Size:	51.0 KB 
ID:	2094   Click image for larger version. 

Name:	Avira Update 3.jpg 
Views:	3 
Size:	44.3 KB 
ID:	2095   Click image for larger version. 

Name:	Avira Update 4.jpg 
Views:	2 
Size:	49.7 KB 
ID:	2096  

    Click image for larger version. 

Name:	Avira Update 5.jpg 
Views:	3 
Size:	39.1 KB 
ID:	2097  

  7. #7
    The scan came up clean. I'm going to set up the weekly scans and whatnot now.

    EDIT: Done doing that too.
    Last edited by KamikazeKarrot; 12-29-2011 at 06:13 AM.

  8. #8
    Join Date
    Aug 2006
    Location
    The Middle
    Age
    80
    Posts
    4,079
    Great. Next program you should put on there is SpywareBlaster from Javacool.

    http://www.javacoolsoftware.net/down...tersetup45.exe

    It is also FREE, does NOT run in the background but blocks spyware, adware, browser hijackers, and dialers.

    • Prevent the installation of ActiveX-based spyware and other potentially unwanted programs.
    • Block spying / tracking via cookies.
    • Restrict the actions of potentially unwanted or dangerous web sites.

    Download, Install, Update, Enable ALL protection and close the program. That's it. I has updates every couple weeks and those must be gotten manually. Open the program, check for updates and if there are any download them and then again Enable All Protection and close the program.

    There are also some unnecessary auto starting programs going there and they run all the time, even when not needed.

    I recommend CodeStuff Starter for that:

    http://www.snapfiles.com/get/starter.html

    Download and install the program. Then when you open it there are three tabs. Startups(the programs that auto start) Processes (same thing as the Task Manager) Services (same as Windows services)

    Open the program, click the Startup Tab and take the check marks out of these programs, none of them need to auto start and all can just as easily be run manually:
    Facebook Update
    Adobe Reader Speed Launcher
    APSDaemon
    iTunesHelper
    QuickTime Task
    SunJavaUpdateSched
    Malwarebytes' Anti-Malware

    After you have removed the check marks, close the program. Next time the computer is started these won't auto start any more.

  9. #9
    Done and done.

  10. #10
    So are we basically all cleared up, then? Infection dead? Break out the party hats?

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •