Author Topic: [Resolved] Blue screen and computer locked  (Read 3367 times)

0 Members and 1 Guest are viewing this topic.

Offline PGB

  • Bronze Member
  • Posts: 253
Re: [In Progress] Blue screen and computer locked
« Reply #30 on: August 21, 2011, 02:12:57 PM »
Trojan:Win32/Alureon.DX was detected and then removed. ...succeeded. 

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22623
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Blue screen and computer locked
« Reply #31 on: August 21, 2011, 02:27:17 PM »
Can you tell me the file name and location that was infected?

Consumer Security

If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

Offline PGB

  • Bronze Member
  • Posts: 253
Re: [In Progress] Blue screen and computer locked
« Reply #32 on: August 21, 2011, 02:47:20 PM »
The items that were detected on my computer:

Trojan:Win32/Alureon.DX
Trojan:Win32/Alureon

file:C:\Documents and Settings\Administrator\Application Data\Sun\Java\Deployment\cache\6.0\14\71d2f5ce-7a4ce32a
file:C:\Documents and Settings\Administrator\Local Settings\temp\24.tmp

Offline Hoov

  • Malware Removal Mentors
  • Global Moderator
  • Diamond Member
  • Posts: 22623
  • Unwilling part owner of Gov't. Motors and Chrysler
    • Hoov's Personal Site
Re: [In Progress] Blue screen and computer locked
« Reply #33 on: August 21, 2011, 03:04:04 PM »
1.Download and scan with CCleaner
When you get to the website, there is a dark grey box on the left side with two tabs along the top. Inside this Dark Grey box is a light grey box. Below that light grey box is where the download links are at. The pay amount is for paid support.
2. Before first use, select Options > Advanced and UNCHECK "Only delete files in Windows Temp folder older than 48 hours"
3. Then select the items you wish to clean up.
In the Windows Tab:

    • Clean all entries in the "Internet Explorer" section except Cookies if you want to keep those.
    • Clean all the entries in the "Windows Explorer" section.
    • Clean all entries in the "System" section.
    • Clean all entries in the "Advanced" section.
    • Clean any others that you choose.


    In the Applications Tab
      • Clean all except cookies in the Firefox/Mozilla section if you use it.
      • Clean all in the Opera section if you use it.
      • Clean Sun Java in the Internet Section.
      • Clean any others that you choose.


      4. Click the "Run Cleaner" button.
      5. A pop up box will appear advising this process will permanently delete files from your system.
      6. Click "OK" and it will scan and clean your system.
      7. Click "exit" when done.


      Your scan showed one of more viruses in your Sun Java Runtime Environment (JRE) cache. Delete those by clearing the JRE cache. To clear the Java Runtime Environment (JRE) cache:
      • Click Start > Control Panel.
      • Double-click the Java icon in the control panel.


      -The Java Control Panel appears.

      • Click Settings under Temporary Internet Files.


      -The Temporary Files Settings dialog box appears.

      • Click Delete Files.


      -The Delete Temporary Files dialog box appears.

      -There are three options on this window to clear the cache.
      • Delete Files
      • View Applications
      • View Applets
      • Click OK on Delete Temporary Files window.


      -Note: This deletes all the Downloaded Applications and Applets from the cache.

      • Click OK on Temporary Files Settings window.
      • Close the Java Control Panel
      You can view those instructions along with graphics Here


      After you have done this, I would like you to go back into the event viewer logs as you did before, and instead of selecting save select clear. You will be asked if you want to save the logs, that is your choice. I don't need them. Then I want you to run your computer normally until tomorrow morning, except I would like you to reboot the computer several times, then I would like you to post new event viewer logs.

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #34 on: August 22, 2011, 06:23:42 AM »
      Done.  The computer has now been  running "csisp" and peppy!  I'm loving it!
      The new event viewer logs are attached.

      Offline Hoov

      • Malware Removal Mentors
      • Global Moderator
      • Diamond Member
      • Posts: 22623
      • Unwilling part owner of Gov't. Motors and Chrysler
        • Hoov's Personal Site
      Re: [In Progress] Blue screen and computer locked
      « Reply #35 on: August 22, 2011, 10:11:07 AM »
      There are two services not starting, but they appear to be related to programs that have been uninstalled. Other than that, there are a few other errors that are for the search service. In my experience, that problem will solve itself.

      Are you having any problems at all?

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #36 on: August 22, 2011, 12:23:31 PM »
      Noproblems noted. The system has been running "crisp" -- quickly responsive.  I'm liking it.

      Offline Hoov

      • Malware Removal Mentors
      • Global Moderator
      • Diamond Member
      • Posts: 22623
      • Unwilling part owner of Gov't. Motors and Chrysler
        • Hoov's Personal Site
      Re: [In Progress] Blue screen and computer locked
      « Reply #37 on: August 22, 2011, 12:58:23 PM »
      Now  there are a few thing's you need to do to fully clean your system and keep it secure.

      Run OTC
      Download OTC to your desktop and run it
      Click Yes to beginning the Cleanup process and remove these components, including this application.
      You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.

      Cleaning out Temporary Files etc. There are several different products that you can use for this. You can go thru the Internet Options in the windows Control Panel. There are several programs that also do the job better than windows does it, in my opinion. There is System Security Suite, EasyCleaner, Ccleaner. Also sometimes other program sometimes do it as well as what you originally got it for like ZoneAlarm Security Suite. Just make sure to keep them updated and use them regularly.

      Disable and Enable System Restore.
      I recommend you turn off System restore, and then turn it back on so that you will not be able to restore your problems to a clean computer.
      For Vista use these instructions, Windows Vista Restore Guide
      For XP use these instructions, Windows XP System Restore Guide
      Reboot
      Re-enable system restore with instructions from tutorial above
      Create a System Restore Point
      Go to all programs, then to accessories, then to system tools, then to system restore. Check the box for create restore point (not select a restore point), then click next and follow the instructions.

      Make your Internet Explorer more secure - This can be done by following these simple instructions: (unless you are using ZoneAlarm Security Suite or something similar, then you would secure the browser thru the firewall). There are some good basic instructions for that here.

      Use a different browser other than  IE (most exploits are pointed towards IE). One of them is
      Firefox.
      It is also worth trying Thunderbird for controlling spam in your e-mail.

      Always use an UPDATED anti-virus program Make sure you update this at least weekly, if not more often. This is one thing that may save you more than anything else.

      Run malware scanners. Three free ones are Spybot Search and Destroy, and AdAware and Malwarebytes' Anti-Malware

      Always use a firewall.
      Any firewall is better than none, and you should pick a firewall that you will use, as even the best firewall is worthless if you turn it off.
       
      Learn how to use your firewall Only programs that need it should have access to the net. But these are specific to the firewall you use, so you will need to learn how. Several firewalls have support forums here. My page will help you with ZoneAlarm if that is what you choose. 


      Never run two Antivirus programs or two Firewalls  at the same time. They can interfere with each other and cause problems. Some people swear that more protection is provided, but the reverse is true. They tend to argue amongst themselves and end up leaving holes. Now I have more than 1 AV installed on my computer, and I keep them up to date. I only run one at a time, but each program has weakness's, so I keep a backup in case my computer starts acting up.


       MOST IMPORTANT : Windows and IE, and whatever other software that you have that connects to the net, needs to be kept updated. The reason is, these programs connect to the net, and if there is an internal security problem, you have already told your firewall to allow the communication, and thus you will have allowed a hole. UPDATES are important. I suggest that you make sure that Windows Updates and the updates for your antivirus and antimalware programs are set for automatic updates. I also suggest running Secunia PSI. It will monitor the software you have installed and let you know when something needs to be updated.

      Don't ever use P2P or filesharing software Even the safest P2P file sharing programs that do not contain bundled spyware, still expose you to risks because of the very nature of the P2P file sharing process. By default, most P2P file sharing programs are configured to automatically launch at startup. They are also configured to allow other P2P users on the same network open access to a shared directory on your computer. The reason for this is simple. File sharing relies on its members giving and gaining unfettered access to computers across the P2P network. However, this practice can make you vulnerable to data and identity theft. Even if you change those risky default settings to a safer configuration, the act of downloading files from an anonymous source greatly increases your exposure to infection. That is because the files you are downloading may actually contain a disguised threat. Many very malicious worms and trojans, such as the Storm Worm, target and spread across P2P files sharing networks because of their known vulnerabilities.

      Before using any malware detection / removal software Check with Rogue/Suspect Spyware List That way you will know if the program you are looking at is on the up and up. If you want to know how it stacks up against other programs check out SpywareWarrior

      We have a good guide here at Spyware Hammer on how to prevent Malware in the Future. You might want to peruse this and follow the recommendations in there.
      PLEASE READ IT AND FOLLOW THE RECOMMENDATIONS TO PROTECT YOURSELF.

      Let us know if you have any more problems, either new or old.
      Have a good time surfing the net, but stay safe.
      If you have no more problems, let me know and I will mark this as resolved. Or if you have more questions, ask away, that is why I am here.

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #38 on: August 22, 2011, 07:08:42 PM »
      'm adding Spybot, Adaware and Secunia PSI.  I'm confused about the Teatimer -- what that means in Spybot -- would';t that interfere with my MSE?

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #39 on: August 23, 2011, 07:42:52 AM »
      Ad-Aware found Trojan-Downloader.Win32.Generic.L
      If you want I can provide the log in the response or as an attachment.  Let me know.

      Offline Hoov

      • Malware Removal Mentors
      • Global Moderator
      • Diamond Member
      • Posts: 22623
      • Unwilling part owner of Gov't. Motors and Chrysler
        • Hoov's Personal Site
      Re: [In Progress] Blue screen and computer locked
      « Reply #40 on: August 23, 2011, 03:00:21 PM »
      If you have an Antivirus then you should not run AdAware. There is a built in Antivirus in there. As for Teatimer, it is a sort of always on protection from malware. It does work, but I like Malwarebytes' Anti-Malware better for my always on protection from malware. I keep Spybot installed and use the immunize feature and the occasional scan. I am not sure if Teatimer would interfere with MSE.

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #41 on: August 23, 2011, 05:03:28 PM »
      Thanks for the explanation; that helps!

      What about the Trojan Downloaderthat was found?  ... a new infection since yesterday?  would a MalwareBytes scan have found it?

      You receommend that Iuninstall Adaware?

      Offline Hoov

      • Malware Removal Mentors
      • Global Moderator
      • Diamond Member
      • Posts: 22623
      • Unwilling part owner of Gov't. Motors and Chrysler
        • Hoov's Personal Site
      Re: [In Progress] Blue screen and computer locked
      « Reply #42 on: August 23, 2011, 05:35:21 PM »
      Can you give me the file and location that the Trojan was found in?

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!

      Offline PGB

      • Bronze Member
      • Posts: 253
      Re: [In Progress] Blue screen and computer locked
      « Reply #43 on: August 23, 2011, 06:11:31 PM »
      Quarantined items:
      Description: c:\documents and settings\administrator\local settings\application data\nova development\productupdate\227.exe Family Name: Trojan-Downloader.Win32.Generic.L Engine: 3 Clean status: Success Item ID: 1 Family ID: 0 MD5: 2074e1e3a550727aebe6bd8773a3a4e3

      Offline Hoov

      • Malware Removal Mentors
      • Global Moderator
      • Diamond Member
      • Posts: 22623
      • Unwilling part owner of Gov't. Motors and Chrysler
        • Hoov's Personal Site
      Re: [In Progress] Blue screen and computer locked
      « Reply #44 on: August 23, 2011, 06:53:15 PM »
      Do you have any software from this company?

      Consumer Security

      If I am helping you and you don't hear from me for 24Hrs, send me a PM Please!