Live Chat & Podcast at 1:00PM Eastern on Sunday!
There's no such thing as a stupid question, but they're the easiest to answer.
JoinTour
Login
Search
General Security
Tag Cloud
access acer asus bios bsod computer crash desktop driver drivers error ethernet excel freeze gaming hard drive hardware hdmi internet laptop malware memory modem monitor motherboard network printer problem ram registry router security slow software sound toshiba trojan ubuntu 11.10 uninstall usb video virus vista wifi windows windows 7 windows 7 32 bit windows 7 64 bit windows xp wireless
Search
Search for:
Tech Support Guy Forums > Security & Malware Removal > General Security >
Looking for advice

Reply  
Thread Tools
ryanryan007's Avatar
Member with 48 posts.
 
Join Date: Jan 2008
Experience: Beginner
18-Jan-2008, 04:04 AM #76
Wow thanks alot Byteman, i appreiciate all the time and effort and help u gave me. now that this problem is resolved..how can i prevent this from happening. So far i plan on getting the comodo firewall, and upgradeding my SAS program. any other programs u suggest i install or remove? so far i have tuneup utilities 07, lavasoft ad aware, avast and now SAS. should i add more to my secruity or keep it the way it is?

ps. can i uninstall hte programs that were recently installed for the cleanup (combofix and hijackthis)?
ryanryan007's Avatar
Member with 48 posts.
 
Join Date: Jan 2008
Experience: Beginner
18-Jan-2008, 10:40 AM #77
i just ran a full scan using my upgraded SAS..and it found "Unclassified Oreans32" :S

what do i do? its already quarantined..is that enuff?
Byteman's Avatar
Moderator & Malware Removal Specialist with 17,387 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
18-Jan-2008, 05:20 PM #78
Hi, It depends on where the item was found it may have been in the already Quarantined items, ComboFix backups, etc.

Can you post the log of that scan that found it please....
ryanryan007's Avatar
Member with 48 posts.
 
Join Date: Jan 2008
Experience: Beginner
19-Jan-2008, 09:18 PM #79
sas log
SUPERAntiSpyware Scan Log
Generated 01/18/2008 at 04:24 AM

Application Version : 3.6.1000

Core Rules Database Version : 3377
Trace Rules Database Version: 1371

Scan type : Complete Scan
Total Scan Time : 00:41:24

Memory items scanned : 496
Memory threats detected : 0
Registry items scanned : 6441
Registry threats detected : 0
File items scanned : 44574
File threats detected : 1

Unclassified.Oreans32
C:\QOOBOX\QUARANTINE\C\WINDOWS\SYSTEM32\DRIVERS\OREANS32.SYS.VIR










scan 2


SUPERAntiSpyware Scan Log
Generated 01/18/2008 at 01:06 PM

Application Version : 3.6.1000

Core Rules Database Version : 3382
Trace Rules Database Version: 1376

Scan type : Complete Scan
Total Scan Time : 00:40:31

Memory items scanned : 454
Memory threats detected : 0
Registry items scanned : 6440
Registry threats detected : 0
File items scanned : 44724
File threats detected : 2

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@atdmt[2].txt
C:\Documents and Settings\Owner\Cookies\owner@ads.bridgetrack[1].txt






scan 3


SUPERAntiSpyware Scan Log
Generated 01/18/2008 at 05:45 PM

Application Version : 3.6.1000

Core Rules Database Version : 3382
Trace Rules Database Version: 1376

Scan type : Complete Scan
Total Scan Time : 00:40:55

Memory items scanned : 451
Memory threats detected : 0
Registry items scanned : 6440
Registry threats detected : 0
File items scanned : 44732
File threats detected : 1

Adware.Tracking Cookie
C:\Documents and Settings\Owner\Cookies\owner@atdmt[1].txt
Byteman's Avatar
Moderator & Malware Removal Specialist with 17,387 posts.
 
Join Date: Jan 2002
Location: NY
Experience: Junkware Jouster
19-Jan-2008, 10:36 PM #80
Hi, Look at the location that was found in....it is the backups folder that ComboFix always makes called Qoobox

The item cannot harm anything there except that, someone could come along and restore the thing, so as a last step, we remove all ComboFix files and folders\\

But, with this tricky type of malware, I like to wait a day or two to clean up the tools as you never know what will happen.

I think it would be safe for you now to delete (there is no uninstall with ComboFix, it is a standalone tool) all ComboFix downloads, files, folders that you have.

ComboFix stores the Qoobox folder in the root of C: drive- it;s not likely that anyone would mess with it there, but if you want to delete Qoobox, do so.

The other items are harmless Cookies> you will always be finding them, there is no need for concern, your scans will remove them.

Also> you can by running Disk Cleanup, or any other temp file cleaner upper like the one I use, CleanUP!

Hijackthis does have an uninstaller in Add/Remove and you can uninstall it if you don't want it around where someone could mis-use it..... others not aware of what they are doing, certainly can cause bad things.
__________________
Mung (computer term), the act of making several incremental changes to an item that combine to destroy it
Donate directly to help the site TSG Library
TSG's Welcome Guide- Tips, Rules, How to use TSG and more!
Reply

THIS THREAD HAS EXPIRED.
Are you having the same problem? We have volunteers ready to answer your question, but first you'll have to join for free. Need help getting started? Check out our Welcome Guide.

Search Tech Support Guy

Find the solution to your
computer problem!




Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
WELCOME TO TECH SUPPORT GUY! Are you looking for the solution to your computer problem? Join our site today to ask your question -- for free! Our site is run completely by volunteers who want to help you solve your computer problems. See our Welcome Guide to get started.
Thread Tools



Facebook Facebook Twitter Twitter TechGuy.tv TechGuy.tv Mobile TSG Mobile
You Are Using:
Server ID
Advertisements do not imply our endorsement of that product or service.
All times are GMT -4. The time now is 10:30 PM.
Copyright © 1996 - 2011 TechGuy, Inc. All rights reserved.

Powered by Cermak Technologies, Inc.