help, some assistance please

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Neznayka, May 14, 2006.

  1. Neznayka

    Neznayka Private E-2

    hi, this is my problem

    while trying to clean my dads pc (i'm going to post a new thread on that topic seperately), i managed to transfer a virus/malware via floppy disks to my main computer.

    the result
    none of the .exe, .com, .reg, .lnk (i am not sure if there are other extension types that i have not yet noticed) files became unrecognized, thus nothing could properly run on my computer, and all files are blank defaults

    ive managed to find out some info regarding this situation,
    apparently it might be some malware that erases a "folder options" profile on the above mentioned file types.

    with a few efforts i was able to restore temporarily the working ability of the .exe files, to run some scans, until the efforts were reset, and .exe files became unrecognizable again

    having gone through the procedure of terminating malware here are the results:
    1. Microsoft Malicious Software Removal Tool -- found nothing
    2. Ad-Aware Full System Scan -- showed the system is clean
    3. Spybot Search & Destroy -- fixed some windows update options
    4. CounterSpy -- scan history attached
    5. BitDefender -- scan history attached, it was able to identify an infection of Junkie.1027 virus
    6. Panda Active Scan -- found no problems, i was not able to find a way of how to save the scan log, i tried twice.
    7. HijackThis -- log file attached

    how can i get my pc back on track please help
    thank you
     

    Attached Files:

  2. Neznayka

    Neznayka Private E-2

    some help please

    okay, i got the .exe, .reg, .com, .lnk problem resolved last night, was a long night but got that settled

    now could some one help me with the removal of the Junkie.1027 virus
    that only bitdefender seems to find?

    are there problems with the hijackthis.log?
     
  3. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Junkie.1027 is a Boot sector virus, and a very old one at that. It is basically harmless, by that I mean it does not destroy any data on your drive, however it does attach approxiamately 1kb code to the end of COM and EXE files and decreases sytem memory by about 3kb.

    To clean this virus from your boot sector obtain a clean, uninfected bootable floppy diskette. Download Bootscan.exe.
    1. DO NOT download Bootscan.exe on an infected computer or with an infected floppy disk.
    2. NOT NOT create a startup disk on an infected computer or with an infected floppy disk.
    Download the Command Line Scanner bootscan.exe
    1. Start the download.
    2. Select Save this file to disk.
    3. Click OK.
    4. Save in Desktop.
    5. Click OK.
    Unzip the Downloaded File
    1. Insert a new floppy disk in the A: drive.
    2. From the desktop, right-click emscan.zip.
    3. Click Extract to.
    4. Type A:\
    5. Click Extract.
    Write-Protect the Startup Disk and BootScan Disk
    1. Place floppy disk label side down (metal circle should be visible) on a table with the metal slider facing away from you.
    2. Locate the write protect tab in the lower right hand corner of the disk.
    3. Move the tab so that there is an empty space below it.
    4. Your disk is now write protected: you cannot accidentally write over it and more importantly viruses will not be able to infect this disk.
    Remove the Virus
    1. Turn off the computer.
    2. Place your startup disk in the A: drive.
    3. Turn on your computer.
    4. Once you're already on the A:> prompt, replace the Startup disk with the BootScan disk.
    5. At the A:>, type BOOTSCAN C: /BOOT /CLEAN
    6. Press the Enter key on your keyboard.
    Once the virus has been removed, remove all floppy diskettes from the computer and reboot from the hard drive.

    This will clean an NTFS Master Boot Record and allow Windows to successfully reboot from the hard disk drive. VirusScan for DOS will not be able to read the rest of the NTFS partition. After starting Windows, run your ASNti-Virus Application to detect and clean Windowsfile infections which may exist.
     
  4. Neznayka

    Neznayka Private E-2

    thanx Shadow_Puter_Dude,
    though this does not solve the problem ... that is if there is one in the first place

    it seems that when i do the bootscan it finds no infection on by boot drive
    one detail i noticed the information you gave me is that this will clean an NTFS master boot record, though i have a FAT32 formatting of my hdd
    maybe that makes a difference with the bootscan
     
  5. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Try it with the /BOOT parameter.

    At the A:>, type BOOTSCAN C: /CLEAN
     
  6. Neznayka

    Neznayka Private E-2

    yeah tried that too,
    either way i scan it finds nothing, system clean

    i've also found k-junkie removal soft and tried that,
    when scanning in ms-dos it haults at a certain point on a specific file
    when i scan in winME the scan completes with no positive results of a virus infection

    yet... bitdefender online scan still finds the virus everytime
     
  7. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    This is a dual boot system?
     
  8. Neznayka

    Neznayka Private E-2

    yeah dual boot
    win me and win xp
     
  9. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    OK, backup any data that you may want to save.

    We are going to rebuild the MBR on the hard drive, doing this could cause you to lose your data on the drive.

    Using a clean bootable Windows ME startup disk, boot to DOS and issue the following command:

    FDISK /MBR

    Note: FDISK must be on your bootable floppy.

    Reboot, and scan the drive.
     
  10. Neznayka

    Neznayka Private E-2

    a few questions of concern...

    what exactly does the MBR do?
    the procedure will affect only the one hard drive i will be fixing?
    how much damage potentially this could cause to the dual boot system... maybe if both will not work afterwards i might was well format now without the need to do the MBR
     
  11. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    The Master Boot Record (MBR), contains vital infornation about your hard drive, file system, and file table. Rewriting the MBR, could corrupt the File Allocation Table (FAT) for Windows ME and the Master File Table (MFT) for WIndows XP; causing you to lose all data on the drive.

    A complete reinstall of the system will not resolve the boot sector virus issue. You will have to replace the MBR.

    Rewritting the MBR and formating the drive is an option.
     
  12. Neznayka

    Neznayka Private E-2

    i guess ill just format the hard drive, when all my stuff is safely backed up, and start a new,

    thanx for the help, greatly appreciate it
     
  13. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Good luck, and remeber to rewrite the MBR before you format the drive.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds