Results 1 to 8 of 8

Thread: "BEFORE You POST"(Please read this Procedure Before Requesting Assistance)

  1. #1
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default "BEFORE You POST"(Please read this Procedure Before Requesting Assistance)



    The FAQ, we have to keep adding when people don't read it so please take the time. We can only help if you help us by following it before starting a topic.

    Malware Removal Forum: volunteers with the following titles above their avatar are authorized to assist members.

    Security Team, Anti-Malware Team, Teacher, Security Expert, Developer.

    Analysts on the Security Team are advanced students whose responses are passed by their teachers, some of whom help here.

    You are in capable hands with any person authorized to assist members in this forum.

    That said, there is always risk involved in installing and removing any software. Even a fix that time has shown to be useful to thousands of users, can present problems to a few or be found to have a bug in development.

    While best efforts are made to assist in removing infections safely, unexpected stuff can happen. It is advisable that you back up your important data before starting any clean up procedure. Neither Safer Networking Forums nor the Analyst providing the advice may be held responsible for any loss.

    Duly noted by members, please start a topic and provide the DDS and aswMBR logs for analysis. No Malware logs are to be posted in any of our other forums.

    Before doing so, read post #2 below, Before you post the DDS and aswMBR logs which also shows how to produce them.
    If the infection prevents you from running DDS and/or aswMBR please start a topic and make note of the situation, provide details of the computer's current symptoms and wait for a response.

    Preliminary Notes:

    • Please backup your Registry with ERUNT, instructions in post #2 below. If you cannot use ERUNT please let us know in your first post so the responder can link you to a different backup utility.


    • Please do NOT turn off System Restore trying to remove an infection. Doing so would only serve to destroy a known restore point (dirty or not) and won't remove the malware. Let your helper advise you as to when a System Restore flush is called for.




    • If one has already run tools/fixes before posting please inform your helper, so that s/he is aware changes may have been made to the system and why. Running fixes before being assisted can destroy evidence in an infection, leaving the malware difficult to detect. Please do not attempt to "do it yourself" while waiting for someone to respond to your topic.


    • Note that all instructions given are customized for that member's personal computer only, the tools used may cause damage if run on a machine with different specs/infections. Please do not take fixes given to another user and apply to your own machine.


    • If someone posts instructions in their own topic, "this worked for me", it will be removed, possibly without notice. Just so you know. Please do not send similar private messages to other members.


    • Posters who start topics at multiple sites for their PC problem waste valuable volunteer resources as our analysts assist people at several forums. Worse scenario would be to run fixes given at one site unbeknown to the person helping the same user elsewhere. If you have already requested help at another site choose where you wish to continue and advise all parties.


    • Do not pm logs or malware removal requests to volunteer helpers, assistance is provided in the forums. The forums are public, if you do not feel comfortable posting logs where they will remain visible please do not start a topic. Otherwise, please use "Preview Post" to check for any personal details such as email addresses you'd rather omit before you "Submit Reply".


    • Please do not start more than one topic for the same computer during the same period. It will either be removed, closed or merged with your original thread.


    • If you have more than one possibly infected computer in the house please let your helper know. Start a new topic for the next machine once the prior thread has been closed.


    • Posting additional comments or logs before a volunteer responds can push you back instead of forward, because your thread ends up with a newer date. In addition helpers would think you are already being assisted because of the post count, they look for topics with a 0 response. For that reason we may merge such posts but please do not count on it.




    • Please do not attach or link to possibly infected files and/or URLS, if an analyst requests files s/he will give you a link to upload them.


    • If your computer shows no symptoms of infection there is no need to post a log in this forum, as in requesting a 'checkup' for no malware removal reason but only to show a log.

    The Waiting Room: Post here if waiting for help four days

    Open Topics moved to archives


    Note:
    When a volunteer posted a response to which you did not reply.

    At this time threads may now be closed three days after last post in topic at the discretion of the volunteer. Please subscribe to your topic so you know
    when a reply has been posted. If the topic has been archived and you still require help start a new topic and include fresh DDS & aswMBR logs with a link to your previous thread. Please do not post any other logs, you'd be starting fresh.


    Please remember, it takes time to analyze logs and prepare a response. When a helper does so and the person does not follow up, it has already slowed assistance for other members.

    The reason being that volunteers help users at several sites, and take X number of new topics daily in order to give each member their attention, and avoid burnout.

    Thank you.



    Towards the end of a cleanup please make sure you follow through with any final log requested, even if it appears to you that your computer is back to normal operation, and when asked to post back one more time please do so. As much as we like our members we would rather not see you back in a few weeks because the disinfecting wasn't finished and final instructions given.

    Along the same vein, this free service is provided by volunteers to assist in the removal of malware from personal computers and provide useful information to prevent an infection from happening again. Although "stuff happens", a helper's intention is not to repeatedly remove malware from the same member's machine/s.

    Our volunteers appreciate your letting them know if they have helped.


    ---------------------------------
    Subscriptions

    Members can keep track of their threads and choose how to be notified about updates.
    ---------------------------------
    Can I edit my own posts?

    1. In the Malware Removal Forum, members may not edit their posts.
    2. In the Spybot-S&D forum and others, there is a 15 minute time frame to edit one's post. It lessens the chance of an answer referring to things the original poster has deleted.


  2. #2
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default Before you post the DDS and aswMBR logs

    Please back up your registry!

    • Download ERUNT The Emergency Recovery Utility NT Registry Backup and Restore for Windows NT/2000/2003/XP/Vista

    NOTE: Installing ERUNT may also install the "registry optimization tool" "NTREGOPT" by default. Please do NOT run NTREGOPT.

    Registry Cleaners, not recommended


    • Save ERUNT to your desktop. Run and install this program.
    • In the box that opens ONLY choose "System registry"
    • Click OK.
    • Click save and then go to File > Exit.

    This is so the registry can be restored to this point if we need it. If you cannot use ERUNT please let us know in your first post so the responder can link you to a different backup utility.

    ``````````````````````````````````````````````````````
    Instruction for producing the DDS and aswMBR logs

    DDS Log


    Download to your desktop DDS from one of the links below:

    Link 1
    Link 2

    • Double click the tool to run it.
    • If a black Screen opens, just read the contents and do nothing.
    • When the tool finishes, it will open 2 reports, DDS.txt and attach.txt
    • Copy/Paste the contents of 'DDS.txt' into your post. Please do not use code wrap.
    • 'attach.txt' should be zipped using Windows native zip utility and attached to your post. Compress and uncompress files (zip files)



    aswMBR Log

    Important! Please do not perform any fix options offered in aswMBR

    Please download aswMBR to your desktop.


    • Double click the aswMBR icon to run it.
    • Click the Scan button to start scan.
    • If you are asked to update the Avast Virus database please allow it to do so.
    • When it finishes, press the Save Log button, save the logfile to your desktop and post its contents in your reply with the DDS logs.






    If the infection prevents you from obtaining logs please start a topic and make note of the situation, provide details of the computer's current symptoms and wait for a response.
    Do not post other logs or use "code wrap" unless requested in that format.

    ---------------------------------------------------------------------------------------------------------------

    When Spybot-S&D version 1.6.2 is installed

    TeaTimer needs to be disabled so that its protection does not interfere with fixes.

    How Spybot-S&D protects against the installation of Spyware/Malware.

    TeaTimer can be re-enabled once the computer is clean.

    1. Open Spybot-S&D in Advanced Mode.
    2. If it is not already set to do this go to the "Mode" menu and select "Advanced Mode".
    3. On the left hand side, click on "Tools".
    4. Then click on the Resident Icon in the List.
    5. Uncheck "Resident TeaTimer" and OK any prompts.
    6. Restart your computer.

    Spybot-S&D Log

    If Spybot-S&D has detected items it cannot remove, please produce the top of the log showing the items flagged and the version of Spybot-S&D.
    Please do not attempt to post the entire log as it won't fit in to the one post and is not needed unless requested.

    • Open SpyBot.
    • Check for problems.
    • When the scan completes, right click on the results list, select "Copy results to clipboard".
    • Paste (Ctrl+V) those results into your new topic, along with your DDSand aswMBR logs.

    `````````````````````````````````````````
    Questions regarding Spybot-S&D support can be asked here: Spybot-S&D Forums

    Note:
    During the running of a Spybot scan ("Check for problems") the status bar in the lower left hand corner of the screen displays the products Spybot-S&D is currently searching for.

    It does not mean that these items are on your PC and is no reason to post a log based solely on the status bar.

    ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

    Corporate, Government, Small Business or Institutional machines? Please see: Personal computers

    Last edited by tashi; 2010-08-20 at 21:32. Reason: Tweak
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  3. #3
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default On-Line Analyzers

    If you have used a machine analyzer, (not recommended), and 'fixed' items before requesting advice, please inform your human analyst so they are aware.

    Thank you.
    Last edited by tashi; 2007-08-09 at 21:54. Reason: tweak
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  4. #4
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default You and Windows, a joint effort

    Note:
    We do not support the use of illegal Pirated/Warez/Cracked software.

    If seeking help in our Malware removal forum please know that users who have programs obtained by such methods will be asked to remove them, since our help could otherwise be seen as aiding copyright violations. Aside from the legalities be aware malware authors prey on users looking to circumvent a software's protection mechanisms. There is a high risk of infection involved in downloading and running crack codes.

    "IDC Study on the Dangerous World of Counterfeit and Pirated Software"
    http://www.play-it-safe.net/


    Microsoft Malware Protection Center
    http://blogs.technet.com/b/mmpc/arch...d-keygens.aspx
    ​As we first reported in the Microsoft Security Report Volume 13, Keygens have become the number one threat reported by users of Microsoft antimalware products. The research also indicates that 76 percent of users that downloaded Keygen or software cracks were also exposed to other, more dangerous malware.

    Keygens are typically not very dangerous on their own. However, malware authors are having great success using deceptive downloads that either pretend to be Keygens or contain them as well as other malware to spread their malicious payloads. Customers reporting Keygens have higher rates of additional malware infections compared to other threats. Some of these threats try to trick users into paying for software that’s distributed for free from trusted sources.
    Please have a legitimate copy of Windows or your topic will be closed.

    --------------------------------------------

    P2P programs -Torrents

    • It is the volunteer analyst's choice to ask you to uninstall the clients before they continue providing help.

    File Sharing, otherwise known as Peer To Peer. (P2P)

    Edit: http://nakedsecurity.sophos.com/2012/09/06/honeypot-monitoring-bittorrent-downloaders/
    ----------------------------------------------------

    Note:

    Helpers in malware removal forums are unlikely to respond and try to clean an operating system that is no longer supported and therefore cannot be updated or patched.

    Further, the tools most often used for manual removals do not work on legacy systems.

    ---------------------------

    Thank you for your understanding and assisting in keeping the net a safer place for everyone.
    Last edited by tashi; 2012-09-06 at 16:47. Reason: Update.
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  5. #5
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default Personal computers

    The malware removal forum is set up to help those in need of assistance with their personal computers. This service is free and provided by volunteer analysts.

    When the infection is on a Company/Business/Institution/Medical Facility-Health Insurance (HIPAA Privacy Rule) machine or any computer used in the workplace.

    The intention of this forum is not to replace a company's IT department or a private business specialist, helpers cannot anticipate alterations or configurations that may have been made to a business machine, or how it will interact with the tools commonly used in the removal of malware.

    Other considerations:

    • Company information may show in the logs.
    • More than one machine could be at stake.
    • If sensitive material has been compromised by an infection, the company could be held liable.

    To prevent possible loss or corruption of company information, please inform your IT Professional or Supervisor when a workplace computer has been infected. If neither are available please consider calling in a local technician who can see the machine/network in person.

    It's not that we don't want to help, but there are too many issues that could arise with company machines and/or servers that malware forum volunteers are not experienced in dealing with.

    Thank you for your understanding.

    Note

    October 12, 2012

    "With the rise of ransomware in the recent quarter, enterprises are increasingly at risk when end-users circumvent corporate policies, especially on personal devices."

    http://www.zdnet.com/ransomware-risk...od-7000005673/

    ------------------------------------------------------
    Home Users

    "Spybot - Search & Destroy® is still free for private use but now we also have more advanced products for our home users that provide more than just protection.
    With our new range of products users can remove annoying startup programs, securely delete files to ensure confidentiality or backup up important registry settings."

    http://www.safer-networking.org/private/

    Overview for the following users, thank you.

    Spybot S&D Corporate Edition, Technician Edition, Small Business Edition and sbNet.
    http://www.safer-networking.org/business/

    We offer a 50% rebate for schools and universities (where the number of users/machines is staff only) and other non profit organizations. At the universities staff computers need to pay for a license, those systems used for education only (the students) are free.

    For more information please send an email to
    http://forums.spybot.info/showthread...4554#post44554

    Best regards.

    -----------------------------------------------------------------------------------------------------------------------------------------------------------------
    -Stopbadware.org
    Information for Website Owners
    ------------------------------------------------------------------------------------------------------------------------------------------------------------------
    If you are removing malware for paying customers, please don't post the logs here as our analysts are volunteers and not here to support such.
    Last edited by tashi; 2013-02-11 at 18:18. Reason: Added information.
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  6. #6
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default Bump and Topic May Be Closed

    Sometimes within hours or a day a user may bump their new topic in an effort to get it back to the top of the page.

    "Any help?" "Anyone there?" "Bump", etc.

    Our volunteers are really doing their best to assist as many members as possible bumping could get your topic closed and you'd need to start again. Remember too that adding posts to a topic removes the zero response analysts search for, so bumping accomplishes the opposite of the desired effect.

    "BEFORE You POST"(Please read this Procedure Before Requesting Assistance)

    Post here if still waiting for help in the Malware Forum, (AFTER) FOUR days

    Thanks.
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  7. #7
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default

    Updated to include aswMBR log.
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

  8. #8
    Member of Team Spybot tashi's Avatar
    Join Date
    Oct 2005
    Location
    USA
    Posts
    30,472

    Default

    Nudge to top.
    UNITE-ASAP

    Microsoft MVP. Consumer Security 2006-2013

    Please help us improve Spybot, download our distributed testing client

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •