BleepingComputer.com: Symantec Corp autoprotect popped up out of nowhere and started blocking downloaded infections for period of one hour, then stopped by itself

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

Symantec Corp autoprotect popped up out of nowhere and started blocking downloaded infections for period of one hour, then stopped by itself

#31 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 30 May 2011 - 03:22 PM

Can you please remove eXplorer.exe as it was detected as being malicious.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#32 User is offline   J.Aza 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 28-May 11
  • Gender:Male
  • Location:Brooklyn, NY

Posted 31 May 2011 - 10:33 AM

Hi cryptodan,
after my last post I realized that it wasn't a gamers scan log just a preamble so i immediately ran the scan per instructions. That scan has been running some 19 hours now with the last 14 or 15 being just inside my [rather large] t-bird local msg store. Is there anyway to tell gametes to ignore the t-bird store and move on?
I fear this has yet to take an incredible amount of time and the PC is needed.

Thanks for help thus far.

J.

#33 User is offline   J.Aza 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 28-May 11
  • Gender:Male
  • Location:Brooklyn, NY

Posted 31 May 2011 - 10:35 AM

BTW of the initial items displayed (SSDT, devices and attacged devices, etc)
None are flagged as suspicious/red. Just fyi.

J.

#34 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 31 May 2011 - 01:17 PM

So GMER is taking 19 hours?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#35 User is offline   J.Aza 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 23
  • Joined: 28-May 11
  • Gender:Male
  • Location:Brooklyn, NY

Posted 31 May 2011 - 02:15 PM

yes. I let it go another hour and then had no choice but to stop it. When I stopped it, it was still in the message store. The PC was needed and could not be held off further. As the initial scans (which I assume were active RAM, registry, MBR, etc..) detected nothing suspicious is it a fairly safe assumption that the machine is clean?

If not, I will begin this process again next week/end when I can alot more time. Is there a way to make gmer skip/ignore the mozilla message store or will I have to move it off the drive for that?

Thanks,
J.

This post has been edited by J.Aza: 31 May 2011 - 02:15 PM


#36 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,386
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 31 May 2011 - 03:21 PM

Just ignore gmer for now, and rescan with malwarebytes, sas and post the logs.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users