PDA

View Full Version : MBAM v SPYBOT



truckersmom
2009-03-06, 20:37
Did a MBAM and AVG scan before installing Spybot and showed no malware or infections. After spybot scan it showed malware in the HKEY reg (6 of them)They all have the same URL" eacceleration.com". Have no Idea who or what their purpose is. Should I "fix" it or not?

truckersmom
2009-03-07, 00:20
Can I exit out of the spybot without loosing anything or do I have to run some sort of log before I exit out ? And am I in the correct forum?

drragostea
2009-03-07, 04:01
Yes, you are at the correct forum (Support for Spybot-Search&Destroy).

Of course, your system would be left intact if you exit Spybot without removing anything.

Spybot is probably detecting a malicious registry key. I would suggest you fix it because 'eaccleration' is flagged as a malicious site by WOT (Web of Trust).

After you run a scan and fix them can you post a log of the results? You should find it with a right click.

truckersmom
2009-03-07, 04:18
hit the fix it and it ran into a problem and couldn't fix it because it was associated with a file that was running(in memory) but that it could be fix at a restart. should Iclick yes then restart my pc and then do the log?

drragostea
2009-03-07, 04:24
Yes. Try that.

truckersmom
2009-03-07, 05:04
I restarted my pc and the spybot automatically started its scan. There are names coming up on the screen in the scanning box that I have not seen before. One in particularly I hope it's not what it says it is because I don't go there. I may get Email from places like that but it's either junked or spammed out. Can they access your pc even if you don't respond to them?

I'm communicating from my lap top while the pc is scanned. now it has virtumonde.generic. Isn't that a type of virus?

drragostea
2009-03-07, 05:16
Can they access your pc even if you don't respond to them?
No.

What happened after the scan? And the names that you see at the bottom left corner are the products (malware) that Spybot scans for, doesn't mean that is on your machine.

truckersmom
2009-03-07, 05:22
still scanning and that virtumonde is back up there again. it sits there for at least 45 seconds.

truckersmom
2009-03-07, 06:41
I think it's stuck at zlob.downloader.bs It was scanning (in numbers)471572 and stopped at 447597. Is it done? It's been sitting at that number for more than 30 min. What next?
Why am I always having to sign back on?

Matt
2009-03-07, 13:25
Hi truckersmom,

Your computer is infected with Malware, please read the thread "BEFORE you POST"(READ this Procedure BEFORE Requesting Assistance) (http://forums.spybot.info/showthread.php?t=288) carefully, do what tashi wrote there.

After that, please open your own thread in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22), where someone will help you. ;)


Best regards,
-Matt-

tashi
2009-03-15, 17:29
Hello truckersmom,

Archived malware forum topic: http://forums.spybot.info/showthread.php?p=296228#post296228

The log is clean although that does not guarantee a clean slate. I see you are at a few sites posing questions about the computer.

Back to Spybot-S&D, ;) open Spybot Search & Destroy > Help > About and let us know the version and date of last definitions.

Also did you run the program in safe mode.

Best regards.

truckersmom
2009-03-17, 02:13
I'm sorry I didn't respond in time as I am in other forums trying to get my pc healthy again Plus a friend is having problems w/hers (mostly updates that are 2-3 years old)

version:1.6.2.46
date:3-4-09
no I didn't run in safe mode(not exactly sure how ,I know it's one of the F keys)
How often should I scan my PC for ie, spyware & adware ...? I have my av set on a certain time to run a scan although I'm considering changing to a different av.
In advance thank you guys for the help.

drragostea
2009-03-17, 03:03
Prior to scanning in Safe Mode (accessed by tapping the F8 key before the Windows Logo appears) you should update your definitions to the latest (3-11-09).

Then scan again.

For me, I'll usually scan once a week with MBAM and scan with Spybot-Search&Destroy right after the weekly Wednesday updates. A full anti-virus scan for me would be every month.

tashi
2009-03-17, 03:22
Hi truckersmom,



date:3-4-09


Updates: 2009-03-11 (http://forums.spybot.info/showthread.php?t=46602)

Spybot-S&D FAQs and Information
Run in Safe Mode (http://forums.spybot.info/showpost.php?p=23629&postcount=2)

As long as your anti virus program is set to update automatically, scanning once a week might be considered the norm, unless you receive an alert.

How often one scans for spyware would depend on surfing habits, only the user can decide a schedule to fit. :)

So how did I get infected in the first place? (http://forums.spybot.info/showthread.php?t=279)

Best regards.

truckersmom
2009-03-17, 14:47
Thanks, I will do this tonight and let you know the results.

truckersmom
2009-03-18, 17:21
here's the last scan(safe mode) did you want to see any previous scans?

8.03.2009 11:07:31 - ##### check started #####
18.03.2009 11:07:31 - ### Version: 1.6.2
18.03.2009 11:07:31 - ### Date: 3/18/2009 11:07:31 AM
18.03.2009 11:07:35 - ##### checking bots #####

--- Report generated: 2009-03-18 11:08 ---


--- Spybot - Search & Destroy version: 1.6.2 (build: 20090126) ---

2009-01-26 blindman.exe (1.0.0.8)
2009-01-26 SDFiles.exe (1.6.1.7)
2009-01-26 SDMain.exe (1.0.0.6)
2009-01-26 SDShred.exe (1.0.2.5)
2009-01-26 SDUpdate.exe (1.6.0.12)
2009-01-26 SpybotSD.exe (1.6.2.46)
2009-03-05 TeaTimer.exe (1.6.6.32)
2009-03-04 unins000.exe (51.49.0.0)
2009-01-26 Update.exe (1.6.0.7)
2009-01-26 advcheck.dll (1.6.2.15)
2007-04-02 aports.dll (2.1.0.0)
2008-06-14 DelZip179.dll (1.79.11.1)
2009-01-26 SDHelper.dll (1.6.2.14)
2008-06-19 sqlite3.dll
2009-01-26 Tools.dll (2.1.6.10)
2009-01-16 UninsSrv.dll (1.0.0.0)
2009-01-22 Includes\Adware.sbi (*)
2009-03-10 Includes\AdwareC.sbi (*)
2009-01-22 Includes\Cookies.sbi (*)
2009-03-10 Includes\Dialer.sbi (*)
2009-03-10 Includes\DialerC.sbi (*)
2009-01-22 Includes\HeavyDuty.sbi (*)
2009-02-10 Includes\Hijackers.sbi (*)
2009-03-03 Includes\HijackersC.sbi (*)
2009-03-10 Includes\Keyloggers.sbi (*)
2009-03-10 Includes\KeyloggersC.sbi (*)
2004-11-29 Includes\LSP.sbi (*)
2009-03-03 Includes\Malware.sbi (*)
2009-03-10 Includes\MalwareC.sbi (*)
2008-12-16 Includes\PUPS.sbi (*)
2009-03-09 Includes\PUPSC.sbi (*)
2009-01-22 Includes\Revision.sbi (*)
2009-01-13 Includes\Security.sbi (*)
2009-02-10 Includes\SecurityC.sbi (*)
2008-06-03 Includes\Spybots.sbi (*)
2008-06-03 Includes\SpybotsC.sbi (*)
2009-01-28 Includes\Spyware.sbi (*)
2009-01-28 Includes\SpywareC.sbi (*)
2008-06-03 Includes\Tracks.uti
2009-03-10 Includes\Trojans.sbi (*)
2009-03-10 Includes\TrojansC.sbi (*)
2008-03-04 Plugins\Chai.dll
2008-03-05 Plugins\Fennel.dll
2008-02-26 Plugins\Mate.dll
2007-12-24 Plugins\TCPIPAddress.dll

18.03.2009 11:09:07 - ##### check started #####
18.03.2009 11:09:07 - ### Version: 1.6.2
18.03.2009 11:09:07 - ### Date: 3/18/2009 11:09:07 AM
18.03.2009 11:09:16 - ##### checking bots #####
18.03.2009 11:43:44 - ##### check finished #####

--- Report generated: 2009-03-18 11:43 ---

Congratulations!: No immediate threats were found. (Status)



I'll check back tonight for anymore info. Thanks.:cowboy:

tashi
2009-03-18, 17:40
Hello truckersmom,

Those logs show your updates and that after a scan no immediate threats were found. :)

Best regards.

truckersmom
2009-03-20, 05:42
WOW!You mean I'm really Clean? That's great! Now I can focus on finding out how to disable some programs from running at start and remove some things I don't use. PC still runs a little slower then it should but a lot faster then it use to since I started with you guys and Malwarebytes. Thanks to all of you that have helped me to understand my pc a little more then I use to.:bigthumb: