nasty infection. Completed win xp cleaning procedure.

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by whiteboymike, Nov 21, 2008.

  1. whiteboymike

    whiteboymike Private E-2

    Hi all

    Got a very nasty virus and for several hours was not able to access my drives. Kept getting a win32 error when i did so.

    I learned it was a type of worm virus (aurorun.ini) and used teh full cleaning procedure for windows xp found on this fantastic site. Thankfully the pc now seems to be running amazingly and i just wanted to thank all the contributers here.

    I am posting my logs to get any follow up advice etc that you deem is necessarry.
     

    Attached Files:

  2. whiteboymike

    whiteboymike Private E-2

    the rest of my logs are here
     

    Attached Files:

  3. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi and welcome

    We are currently reviewing your logs, please be patient and we will get back to you with a set of instructions as soon as possible.

    Thanks, Kestrel13!
     
  4. whiteboymike

    whiteboymike Private E-2

    many thanks.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You are way out of date with the databases for SUPERAntiSpyware and Malwarebytes. Thus you did not update as requested in the instructions.

    • Uninstall SUPERAntispyware now and download and install the current version.
    • Then choose to update it again to get the current database.
    • Then run a new scan and attach a new log.
    • Then run Malwarebytes and select update to update it to the current version.
    • Run a new scan and attach a new log.
    What problems are you currently still having?


    Your logs are clean other than what was removed already and what I will have you do below. Note you could have infected this PC via a USB flash drive or similar. If you use USB drives, they may be infected and will infect any PC they are plugged into. Check for the below files on all drives including USB drives and delete them if found.

    Autorun.inf
    resycled\boot.com
    resycled <--- this is actually a folder

    Now copy the bold text below to notepad. Save it as fixme.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.
    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
    Last edited: Nov 23, 2008

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds