Is There A New Version Of flec006.exe as I cannot do anything advised

Discussion in 'Malware Help (A Specialist Will Reply)' started by barrym67, May 30, 2008.

  1. barrym67

    barrym67 Private E-2

    Greetings I have some new questions and problems with getting rid of the flec006.exe. I have gone over the READ & RUN me step by step, till when you have to run CCleaner, it will just not engage, nothing happens.

    I have disconnected the infected PC from the Internet as IE took forever to load, my Internet speed was throttled, I could use Firefox and went to Housecall but even that did not work. I could not do a live scan via F-Secure either.

    Norton was killed, I cannot do a system restore, I cannot boot into safe mode (even after adding a recommended registry entry in another thread), I cannot view my hidden files and folders and going to the registry does not help me as the SHOWALL folder is missing in the following key:

    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\
    Advanced\Folder\Hidden\SHOWALL

    I cannot run combofix.exe as it states that it is not a valid win32 application, I cannot run or manually update Super Anti Spyware is as my local files have disappeared under documents and settings where you have to extract the manual updates for Super Antispyware that is here: (For Windows 2000/XP/2003/Media Center the folder is typically located here:
    C:\Documents and Settings\<USERNAME>\Application Data\SUPERAntiSpyware.com\SUPERAntiSpyware), the PC just reboots itself if you try run the scan or ANY other spyware program. I connected the PC to the net to try and do the updates and that did not work either and quickly unplugged it again.

    I have followed many threads on this forum but none of them are helping me as none of the suggested methods and tools do not work on my system. It seems as if the flec006 owner has updated this virus and as I said, none of the suggested removal tools will operate on my system.

    I do not know what to do or where to start. I have been searching the net for hours now and getting nowhere. I am really stumped, does anyone out there have any new advice for me apart from killing my teenage son?!?!?!

    Any help/advice will be appreciated = = = thank you so much!!
     
  2. barrym67

    barrym67 Private E-2

    Oh and by the way, I do not mind formatting my drive, but I have a MAJOR problem, I need to save my raw email (Outlook Express) filed which are in documents and settings (user) local settings, application data etc, but that has been hidden/disabled by the virus (flec006.exe)

    If only I could get those files I do not mind formatting, I will save all my files to another PC, via the network, would this PC get infected too? Then format my drive, install my antispyware and virus protections etc and then copy my data back or is that a bad idea? I do not know of any other, but I can only format if I can get into my application data and well I cannot!! This is really a bad bad virus.
     
  3. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Welcome to Major Geeks!

    The latest for of the malware you have (called W32/Bagle) is quite problematic. It is much more difficult to remove then previous vintages of the same infection. Currently the best solution is manual cleaning using your Winodws CD to boot to the Recovery Console. Do you have your boot CD?

    You could optionally put this CD into another PC as a slave drive and copy your Outlook Files from it. That should be safe to do. Just don't run any executables from this drive.

    A third option is to make (obviously from another PC) the below CD which allows you to boot into a familiar Windows like environment that is running from CD. Thus your real Windows is not running and we can still manually delete the files related to the infection since they are not loaded.

    UBCD4Win
     
  4. barrym67

    barrym67 Private E-2

    Hi There Chaslang

    Thanks so much for responding, but I must let you know how I managed to sort it out, it was a mission though, everything is back to normal but I am going to format anyway, this is one hectic attack let me tell you.

    What I did was i had to by a month sub to PREVXCSI for $15.95 which was money well worth spending and here is the link if anyone wants it:

    http://www.prevx.com/filenames/1659043503788551641-0/PREVXCSI.RAR.html

    THAT is what managed to start the clean up process, killing the files that were now "invisible" as the virus hid all the folders where it was operating from. I followed the instructions that they tell you while scanning. I had turned off system restore as well.

    I then managed to un-install Norton and Zone Alarm and re-install them, did reboots and updated. I had to run prevxcsi a couple of times during this whole process it was not just one east step let me tell you.

    I also ran combo-fix which killed A MILLION things. Combo fix managed to bring everything back to life in the registry, I could once again see the hidden files and folders and the content of my local settings application data etc.

    I downloaded a trial version of Kapersky Anti Virus and everything came up clear. Does anyone have an opinion on the best anti virus software??

    I hope this helps someone else out there who is having the same problem.

    Regards

    Barry
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Prevx CSI is available here for free: Prevx CSI - FREE Malware Scanner

    There are other methods as I stated in my first message for fixing this that may sound complicated but they actually are easier than what it sounds like you went thru.

    I would like to see your ComboFix log and I would like to see logs from the other tools given in our READ & RUN ME cleaning procedure. I want to make sure you got everything. Assuming you are using Windows XP, what I'm referring to is the logs list in the below link (ComboFix is one of those tools).

    Windows XP Cleaning Procedure
     
  6. barrym67

    barrym67 Private E-2

    Hi Chaslang

    Sorry about the late reply but what I did was that I had formatted my drive and I no longer have the reports. I had to pay for Prevx CSI to remove the bad elements.

    I am all set and fresh now with a clean system!!

    Take care

    Regards

    Barry
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Not sure why you had to pay when the tool is supposed to be free.

    Why did you need to format if Prevx worked properly?
     
  8. barrym67

    barrym67 Private E-2

    Well the scan is free, but if it finds malicious elements you have to pay for them to be removed. Well I formatted because that is just the way I am, I really do not trust all the software out there, so I just wanted to make doubly sure and I kind of like a fresh start and perhaps I am a bit compulsive obsessive I suppose, it is just like doing a spring clean I suppose. Maybe it was not necessary but I preferred a format. Took me a week to get back up and running like I want though. :)
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Ah!! I just re-read their info and they only remove simple items for free which means this tools is basically useless since we can remove those kinds of problematic items with many other tools for free and those other truly free tools will also remove problematic malware for free which PrevxCSI does not do.

    You should have decided this before buying Prevx. ;)
     
  10. barrym67

    barrym67 Private E-2

    Well if only I knew, I am inexperienced at this as I do not usually get a virus as I do not do dodgy things, but I was desperate and you learn by your mistakes. But at the time I must say that if it was not for PrevxCSI I would not have been able to access my local settings/application data/identities to save my emails. It is a lesson well learnt and my teenage son is now banned from my PC, I will buy him his own so do any dodgy things the little sh*t.:-D
     
  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    There are other ways! One easy method (well easy for some of us) is to move the infected harddisk into another PC as a slave drive and copy what you want from it. Another method is to use a CD like below (which you have to make) to either remove the infected files or to again copy what you want to another drive.

    UBCD4Win
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds