Micro Billing Systems rmvalid.exe

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by baguabunny, Aug 22, 2007.

  1. baguabunny

    baguabunny Private E-2

    Please Please Help!! I've been on my computer for 10 hours trying to rid myself of this trojan. I've followed all the begginers stuff but when i tried to go back into normal mode to run getkey and shownew my computer completely freezes. I have next to no knowledge about computers. only what iv'e learn't in the past 10 hours! I'm in safe mode at the moment. The scans say they find the problem and clear it but they don't. Really worried my computers screwed. Can only get 1 scan report up aswell. Shall i throw away my computer now??!?!
     

    Attached Files:

  2. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    This is part of the "MicroBillSys Trojan", please try to attach all of the logs. As a reference I will post the below initial instructions.

     
  3. baguabunny

    baguabunny Private E-2

    Have already done "Read and Run me first" Did S&D, Counterspy, bitdefender
    All of them found a file on the computer naming it as MBS rmvalid.exe and all of them appeared to get rid of it. But it then reappears connecting to the net and showing a so called bill i have to pay. I only brushed over the sight and did not give permmision to have it on my computer.
    I have downloaded getrunkey and shownew. I did this before starting this thread. But when i tried to do Panda scan it didn't work in safe mode so i went to go to boot up normal but it is freezing.(The desktop and icons appear but will not work (they work at first but very slowy and then stop)
    So i was and am still unable to get the other reports from the other scans. Just the bitdefender that i attatched on my first post. A bit lost now.
    Can i run getkey, shownew and HJT in safe? Sorry to be so useless.
     
  4. baguabunny

    baguabunny Private E-2

    Managed to get my normal start up working. So i've attatched the report logs
    i can't unfortunatley get Panda to work in either the safe mode or normal.
    So here are the logs. I will then do the high jacker thing as you suggested.
     

    Attached Files:

  5. abri

    abri MajorGeek

    Hi baguabunny!

    It looks like you do have infections and they're not gone. Please try and get the newfiles log from ShowNew if you can and remember to run HijackThis as per the instructions in the READ & RUN ME FIRST.

    Thanks!
     
  6. baguabunny

    baguabunny Private E-2

    Ok. Getting the hang of this now. Here is shownew and also hijack this log.
    Thanks for your help people! Headache seems to lesten with help!!!
    :)
     

    Attached Files:

  7. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Run this utility below and afterwards try the online scans again.
    1. Download this file - combofix.exe
    2. Double click combofix.exe & follow the prompts.
    3. When finished, it will produce a log for you. Attach this log to your next reply
    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  8. baguabunny

    baguabunny Private E-2

    Hi bjgarrick

    Did as you said. Normal mode seems to be speeding up now. I've attatched the combofix log and did a new bitdefender (still can't do panda).

    hope this is everything.

    Bagua bunny:confused
     

    Attached Files:

  9. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Please attach a fresh GetRunKey, ShowNew and HijackThis logs.
     
  10. baguabunny

    baguabunny Private E-2

    Hi

    Done as you've asked and attatched the logs. Everything is moving much more smoothly now but the start up is slow and occasionally on the task bar i keep seeing like a small screen icon flash up moentarily and dissapear. Is that anything to worry about?

    talk soon

    Bagua bunny
     

    Attached Files:

  11. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Step 1:
    Please download ATF Cleaner by Atribune. This program does not require an installation. The executable actually runs the program.

    NOTE: This program is for Windows XP and Windows 2000 only. ATF Cleaner will remove all files from the items that are checked so if you have some cookies you'd like to save. Please move them to a different directory first.
    • Double-click ATF-Cleaner.exe to run the program.
    • Under Main choose: Select All
    • Click the Empty Selected button.
    If you use Firefox browser
    • Click Firefox at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    If you use Opera browser
    • Click Opera at the top and choose: Select All
    • Click the Empty Selected button.
      • NOTE: If you would like to keep your saved passwords, please click No at the prompt.
    Click Exit on the Main ATF Cleaner menu to close the program.

    Step 2:
    Now download The Avenger by Swandog46, and save it to your Desktop.
    • Extract avenger.exe from the Zip file and save it to your desktop
    • Run avenger.exe by double-clicking on it.
    • Check the 'Input script manually' box.
    • Click on the magnifying glass icon.
    • Copy everything in the Quote box below, and paste it in the box that opens:
    • Now click the 'Done' button.
    • Click on the traffic light icon and OK the prompt.
    • You will be prompted to restart, OK the prompt and your PC should reboot, if not, reboot it yourself.
    • A log file from Avenger will be produced at C:\avenger.txt

    Step 3:
    Please download F-Secure's BlacklightBeta
    • Download fsbl.exe and save it to the Desktop.
    • Once saved... double click fsbl.exe to install the program.
    • Click accept agreement and Click scan
    • This application may trigger a warning from your antivirus. Let the driver load. Wait for it to finish.
    • If it displays any items...don't do anything with them yet. Just hit exit (close)
    • It will drop a log on Desktop that starts with fsbl....big number
    Please attach the BlackLight log.
     
  12. baguabunny

    baguabunny Private E-2

    hello

    i have attatched the files as requested. Curiously though since running them the computer has slowed down again?!?

    thanks again for your help. much appreciated

    Bagua Bunny
     

    Attached Files:

  13. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Those logs look ok, attach a fresh HJT, GetRunKey and ShowNew Logs.
     
  14. baguabunny

    baguabunny Private E-2

    Thanks for that will do , been traveling the past few days so sorry for the delay in replying will place logs ASAP

    Cheers

    Bagua Bunny
     
  15. baguabunny

    baguabunny Private E-2

    Hi here arethose fresh logs!:)
     

    Attached Files:

  16. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your logs are clean. If you are not having any other malware problems, it is time to do our final steps:
    1. If we used ComboFix, you can delete the ComboFix.exe file, C:\ComboFix folder, C:\QooBox folder, C:\WINDOWS\nircmd.exe, and the C:\combofix.txt log that was created.
    2. If we had you run Avenger, you can delete all files related to Avenger, the log (avenger.txt) and C:\avenger.
    3. If we had you download any registry patches like fixme.reg, fixme1.reg or fixWLK.reg (or any others), you can delete these files now.
    4. You can delete the ShowNew.Zip and GetRunkey.Zip files and the files that you extracted from the ZIP files. You can also delete the C:\newfiles.txt and C:\runkeys.txt logs that were created
    5. If you are running Windows XP or Windows ME, do the below:
      • go back to step 8 of the READ & RUN ME to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    6. After doing the above, you should work thru the below link:
     
  17. baguabunny

    baguabunny Private E-2

    Thank you so so much. I've nearly completed the downloading of the extras you reccomend to keep my computer clean. thank you for giving your time to help get rid of that damn trojan. I am forever grateful to you!!

    Keep up the good work! AND AGAIN THANKYOU!

    take care

    Bagua bunny:D:wave
     
  18. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Your Welcome!

    Surf Safely!:)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds