Powers1,
Be sure to update MBAM before you run it again.
Powers1,
Be sure to update MBAM before you run it again.
Update.
I have always the latest 4237 version on MBam.
In the last 5 hours ,Avast blocked 2 threats,so in my case ,MBam doesnt seem to be doing anything ???
If you’re on a 32bit system, run a boot time scan with avast…!
asyn
Ok Thanks again,Asyn ,I will run the 32 bit boot time scan with Avast.
I performed a FULL scan with MbAM and still didnt detect anything.?
One thing I am sure of now is that everytime Avast blocks the newoporto.cn site ,I am not able to download anything files with IE!
Everytime,I have to go to security settings and alter to allow file downloads!I had noticed that I had problems downloading files and I even performed a System Restore but I never associated this with the newoporto threat,now I am sure!
Asynmif you remember the first download link you gave me for MBam download,I said my IE was blocking it,so you gave me another link!But I had already altered the security settings,so the last link you gave me ,I was able to download!
Is this happening to anyone else?
You’re welcome…!
Please report back…
asyn
Yesterday.I ran Avast boot time scan on my Vista 32 bit OS…and 3 hours later report shows that I had 3 virus infections and an error.All were successfully moved to CHEST.
The Error was on Mbam set 1.46 file (unknown packer version)
The virus were:
1.WIN32:Malob-BL
2. Trojan-Gen
3. Rootkit-Gen
I was surprised that Avast didnt pick them up on a normal scan ???..
Also,so far this morning ,no more newoporto threats ;D
Thanks for the feedback…!
asyn
Latest 29th June.
All day yesterday Avast Network Shield only blocked 1 Newporto.cn threat…,so I was quite happy ![]()
However,today ,I am being bombarded again…4 times… ???..
Ran Mbam and not catching anything… ???
Anyone else have any feedback or experience?
Thanks guys ![]()
Well, it seems there is still something wrong on your system…!!
I’ll PM essexboy about his thread, he can surely help you to fix this. ![]()
asyn
There does appear to be something amiss
http://www.geekstogo.com/misc/guide_icons/gmer.png
GMER Rootkit Scanner - Download - Homepage
[] Download GMER
[] Extract the contents of the zipped file to desktop.
[*] Double click GMER.exe.
http://img.photobucket.com/albums/v666/sUBs/gmer_zip.gif
[*] If it gives you a warning about rootkit activity and asks if you want to run a full scan…click on NO, then use the following settings for a more complete scan…
[*] In the right panel, you will see several boxes that have been checked. Ensure the following are UNCHECKED …
[] IAT/EAT
[] Drives/Partition other than Systemdrive (typically C:)
[*] Show All (don’t miss this one)
http://www.geekstogo.com/misc/guide_icons/GMER_thumb.jpg
Click the image to enlarge it
[*] Then click the Scan button & wait for it to finish.
[*] Once done click on the [Save…] button, and in the File name area, type in “ark.txt”
[*]Save the log where you can easily find it, such as your desktop.
CautionRootkit scans often produce false positives. Do NOT take any action on any “<— ROOKIT” entries
Please copy and paste the report into your Post.
THEN
Download OTL to your Desktop
[*]Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
[*]Select Scan all users
[*]Under the Custom Scan box paste this in
netsvcs
drivers32 /all
%SYSTEMDRIVE%*.*
%systemroot%\system32\Spool\prtprocs\w32x86*.dll
%systemroot%\system32*.wt
%systemroot%\system32*.ruy
%systemroot%\Fonts*.com
%systemroot%\system32\spool\prtprocs\w32x86*.tmp
%systemroot%*. /mp /s
CREATERESTOREPOINT
%systemroot%\system32*.dll /lockedfiles
%systemroot%\Tasks*.job /lockedfiles
%systemroot%\System32\config*.sav
%systemroot%\system32\user32.dll /md5
%systemroot%\system32\ws2_32.dll /md5
%systemroot%\system32\ws2help.dll /md5
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
[*]Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
[*]When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
[*]Attach all logs please
Hi Essexboy,
I dont know what to say ??? ???
Ran Gmer and after about 5 mins it crashes my computer and I get black screen asking to start windows normally!
I do this ,ran Gmer again and this time I just open program…dont even press SCAN and computer blocks…no mouse control …nothing!Cant even open task manager…Worst! I cant even switch computer off with on/off button ???..Had to remover battery,something I hate doing this! ???
Anyway,I started pc again under “windows normally” and deleted Gmer…and I will now run Avast Boot time scan…and if I find anything I will post here…
I know you guys are trying to help but I am very disappointed!
Hi powers1,
On top of the fact that your country lost out against Spain yesterday, you probably also have hardware problems.
Sometimes leaking condensators may cause more harm then malware all sorts and will give you random error messages,
polonus
Hi Polonus,
Performed Avast Boot time scan and all is clean ![]()
Leaking condensors!Oops!Thats worst!..My laptop is brand new…I hope not!
Portugal lost to a better team with a better coach who made the right subs at the right time!Our coach made a stupid sub and after that came the goal and supremacy for Spain.
Also Ronaldo should have stayed at home!..Maybe he did…only his shadow there…
Back to topic,I still keep getting something like 5 Avast blocks a day… ???
Got used to it now…as long as it doesnt interfere with my system…i just ignore it.
Thanks for replying
Skip the GMER part and move on to the OTL scan
UPDATE.
Almost 2 days that Avast stopped blocking newport.cn threat ;D
I ran Ad-Aware 8.2 and it found and deleted these:-
-WIN32.Backdoor.Papras/A
-WIN32.Trojan.Visel (Visel installs itself as a trojan.It may also download additional files to the infected system)
The Trojan .Visel was infected on a AVS4U.exe file ma video converter software,while the Backdoor.Papras may have been the reason I was getting the newporto.cn threats.
Hope this helps anyone with same problem as me!Also hope it resolved my problem ???
Thanks for the help ,guys,appreciate it.