This thread's last reply is from August 13, 2015, 7:32 AM UTC. Software, malware, and removal-tool
advice below may be out of date — treat specific steps and download links with caution.
Gary R
Thanks for letting me know about Edge. I expect I'm going to have to update a lot of stuff in respect to W10.
It'll take me a while to go through the latest FRST logs, but I'll get back to you ASAP.
Anon67
the windows 10 update is going to require the rewriting of so many tutorials.
unfortunate
thanks for the help and diligence in going through the logs
Gary R
I'm concerned that according to the log the stuff I'm scripting for removal isn't being found when FRST runs its fix.
So can you please run another scan with FRST, so that I can check whether it's still there or not ?
No need to check the Addition.txt button this time, since all I need to see is a Frst.txt log.
Anon67
# DelFix v1.010 - Logfile created 12/08/2015 at 13:50:34
# Updated 26/04/2015 by Xplode
# Username : yisman - YISMAN-PC
# Operating System : Windows 10 Home (64 bits)
~ Removing disinfection tools ...
Deleted : C:\FRST
Deleted : C:\AdwCleaner
Deleted : C:\Users\yisman\Downloads\FRST-OlderVersion
Deleted : C:\log.txt
Deleted : C:\Users\yisman\Desktop\dds.txt
Deleted : C:\Users\yisman\Downloads\Addition.txt
Deleted : C:\Users\yisman\Downloads\adwcleaner_4.208.exe
Deleted : C:\Users\yisman\Downloads\dds.scr
Deleted : C:\Users\yisman\Downloads\esetsmartinstaller_enu.exe
Deleted : C:\Users\yisman\Downloads\Fixlog.txt
Deleted : C:\Users\yisman\Downloads\FRST.txt
Deleted : C:\Users\yisman\Downloads\FRST64.exe
Deleted : C:\Users\yisman\Downloads\Search.txt
Deleted : HKLM\SOFTWARE\AdwCleaner
########## - EOF - ##########
Anon67
the reason I came here was to see if it was possible the story I was given, or if I should pursue this further
they claim someone used my IP address and my username and password to steal a thousand dollars from me
is this believable that someone hacked my computer? Did anything turn up that would suggest this?
I was not using any P2P programs and the last time I opened streamtorrent was a long time ago. The version I had is probably well out of date (when I used it, I used to keep updated).
Gary R
There's nothing I have seen on your machine that suggests you have a key logger or any other kind of remote access trojan on your computer. We can run all sorts of other scans, but my gut feeling is your machine is clean of malware.
That does not preclude the possibility that someone who has had access to your machine may have compromised it in a way that we're not able to test for.
There is also the possibility that the website where your money was stolen has been compromised, but without knowing what type of website, or what type of security procedures they have in place, it's impossible for me to make any judgement on what the likelihood of that is.
Personally, if this were my computer, I would reformat it, because then you can be pretty much 100% sure that any unauthorised changes to it will have been removed.
Anon67
it was a gambling website, but they're not likely to share any of their protocols
thanks for the help
a few questions:
1)What was the reason for scrubbing all my cookies and temp files a second time? It had already been done.
2)Why do the detection programs like FRST and adw need to be removed afterwards? Aren't they useful?
3)Should I download Spybot or Spyware Blaster? You seemed to be saying Spybot is useful but Blaster is not.
Gary R
1. I just do it as a matter of course. Sometimes malware installs a number of "temp" files, which can be used to regenerate an infection, so I "flush" the temp folders to ensure they're clean. Cookies just get taken out as a matter of course because of the way the temp file cleaning routine in FRST works.
2. Programs like ADWCleaner and FRST can be "dangerous" if not used with care, ADWCleaner has been known to flag things that do not need removing, and a scriptable tool like FRST in the hands of someone who isn't fully trained in its use, is like having a live grenade on your machine. Add to that the fact that because of the way they function, they can sometimes be flagged by Anti-Virus scans as "malicious", and you can see why it's easier and safer just to remove them.
3. Personally I believe that both Spybot and Spyware Blaster are beyond their sell by date now, and add very little (if anything) to the security of someone's computer. I don't know of any infection currently doing the circuits that is efficiently removed by Spybot, and the method that Spyware Blaster uses to secure your machine (by adding a large number of sites to the "restricted sites" zone in IE) can result in quite noticeable slowdown in your web browsing.
Whilst we're on that subject, I forgot to advise you to clear out the sites listed in your restricted sites zone, unfortunately when Spyware Blaster is removed, it does not remove all the sites it listed, so you need to do that manually.
To be honest I'm not exactly sure how you do that in W10, where Edge is the default browser, for IE it's ... http://windows.microsoft.com/en-gb/windows/security-zones-adding-removing-websites#1TC=windows-7
Anon67
1)Right but I had done that process earlier, you instructed me to do it already. Then a few posts ago you had me do it a second time.
re: restricted sites
I use Firefox anyway.
If not Spybot or Blaster, what would you suggest for everyday use? I've been using Malwarebytes for five years or so, but I usually like to have multiple programs in case one misses something.
MS Essentials? I have to see if that's on my computer and if it can be enabled.
Gary R
1. As I said, it's habit, whenever I write a fix I include an instruction to empty temp files.
As far as protection goes, personally I use Microsoft Security Essentials (MSE) and Malwarebytes Anti- Malware (MBAM), anything more is IMO overkill, and is more likely to cause conflict problems than to offer any substantive increase to my online safety.
Your browsing habits will have a much greater affect on your security than your choice of defensive programs ever will.
On Windows 8 and later, Windows Defender was updated to the same capability as MSE, and you therefore won't be able to install that program on a W10 machine, because it's already pre-installed under another name. Why Microsoft chose to stick with the Defender name (which had such a bad reputation) is beyond me, but the truth is the new Defender is actually very good.
Anon67
for some reason defender keeps getting disabled and I keep manually enabling it. I never figured out what was going on there. Maybe using an antivirus program shuts it off.
I just did a search. It seems AVG shuts off Windows Defender. I'll just dump AVG.