PDA

View Full Version : unremovable scan problems, yet next scan is clean!



brumman
2008-11-26, 22:08
Hi,
I have installed and run Spybot S&D 1.6, all immunized etc. On my computer (Win2k OS) it found some minor problems which I removed, but it was unable to remove a few Firefox 3 tracking cookies - all shown in red. But next time I ran SB it found no trace of them!
The same problem is occurring on my daughter's WIN XP machine but in this case several nasty trojans were reported - which also could not be removed it seems. However when she ran SB again the scan came up clean! I'm sure the problems, if they were real, are still there. What is happening?
I have generated an HJT log but before sending to the Malware forum thought I'd check here first.

drragostea
2008-11-26, 23:46
I can't be sure what to tell you. Er, do you recall what the results were (not tracking cookies, as they are harmless)?

It sounds a bit spooky cause its like its disappearing and reappearing. Hm. Can you a run anti-virus scan and what it picks up?

brumman
2008-11-28, 01:24
Thanks for the reply.
On my machine I believe they were just harmless tracking cookies but I thought it strange that they were in red and couldn't be removed (all Firefox).
In my daughter's case I think there were 6 different trojans listed - I asked her to run the HJT scan or at least write out the names, but she closed the program since it wouldn't remove or quarantine them. I'll ask her to run a new AVG scan and see what it returns, but as I said she has run S&D twice since and it shows no threats!
Would HJT log show them up and where in it would they most likely be? If anything is shown should she then send the log to the malware forum?
Once again thank you for helping.

drragostea
2008-11-29, 04:41
In my daughter's case I think there were 6 different trojans listed -
The tracking cookies wouldn't be so dangerous at the moment, but it's the trojans that pose a serious threat. Not potential, serious.

So Spybot-Search&Destroy is detecting the trojans? Does AVG pick up anything (AVG 8.x detects both viruses and malware)?
You can always clean out the cookies manually via your browser options, but you can use ATF Cleaner to clean them all out at once:
http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25
-
It's a small file, if you want to download it.

After running ATF or clearing out the cookies+cache (whichever way you want), update Spybot in Normal Mode with all the updates, boot into Safe Mode, disconnect your Internet and scan.

If Spybot actually comes up with something and/or AVG detects a confirmed threat, you'll have to start your own thread in the Malware Removal Forums to purge the threat.

Good luck.

brumman
2008-11-29, 07:37
I actually use CCleaner as well as manual cookie removal - guess it's much the same as ATF.
My daughter tells me that AVG (7.5) found no threats so perhaps her original Spybot scan was false!? However the reason she tried it was because her computer is running very slowly and has not improved after defragging, CCleaner, AVG and Spybot scans!
Incidentally one of the original threats Spybot reported was magicantispy.

drragostea
2008-11-30, 01:57
This is probably a rogue malware installed posing as something legitimate. In addition, your AVG is dated. The current and latest version is AVG 8.0. AVG 8 includes both anti-virus and malware protection+scanning.
-
Consider posting in the Malware Removal (http://forums.spybot.info/forumdisplay.php?f=22) forum and having someone take a look at your system.

If you decide to have an experienced malware removal specialist assist you, please follow the procedure in this link to run scans and produce a HijackThis log: "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) ( http://forums.spybot.info/showthread.php?t=288).
-
Start your own thread in that forum, and they will get your computer cleaned out. Maybe the dated version of AVG is not detecting anything?

And yes, CCleaner and ATF has very similar functions.