Heavily infected

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by hassaan123, Sep 29, 2011.

  1. hassaan123

    hassaan123 Private E-2

    Hello,
    I had alot of virus on my windows xp so I formatted my C drive and installed windows 7 ultimate N fresh copy. But still I feel I am infected. Combofix and root repeal didnt work. I downloaded combofix many times but it gave same error.
    The logs are attached.
     

    Attached Files:

    Last edited by a moderator: Sep 29, 2011
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You definately have a sality infection which it is not good news.

    In the majority of cases, the only way to remove this infection is to reformat and reinstall Windows. Please review the following articles by Microsoft and Symantec about this infection and ways to attempt recovery.

    http://www.microsoft.com/security/po...in32/Sality.AM
    http://www.symantec.com/security_res...011714-3948-99

    Note: If you do attempt to back-up your files and reinstall windows, do not back-up any any executable files ( and note this does not mean just exe files. It means anything that could be considered a binary executable like .com, .dat, .dll, .avi, .mp3, .mpeg, .msi, .pdf, and the list goes on ) just one infected file could respawn the problem!

    Also any writeable removable media you have put in this PC may be carrying the infection
     
  3. hassaan123

    hassaan123 Private E-2

    Well i did install a fresh copy of windows 7 over my windows xp,but still the malware is there. I have a lot of data in my other drives of the hard disk so i wont be able to do complete format of my hard disk.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Then your system will remain infected. ALL executable files on ALL drives/partitions may be infected. And any single one file remaining/backed up, could reinfect the whole PC. You don't have any choice.

    You cannot reinstall over the previous copy. You must delete all partitions, repartition, format all partitions, and then reinstall from scratch. And remember what I stated above, if you keep any backups of executable files and then reuse them, you will have to start all over again, because you will reinfect your PC from the backup.
     
  5. hassaan123

    hassaan123 Private E-2

    Ok so I formatted my hard disk and installed fresh windows 7. But there were few files (pics,programs etc) which I backed up to my USB drive. I am sure that the USB drive would now be infected so before opening it I scanned and removed the virus from it through emsisoft anti malware. The log file is attached. So now is it safe to open and use the back-up? Any other precautions?
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This log shows that you also had Ramnit which is an additional executable file infector. You really need to be more careful.

    Possibly not. Emisoft may not have really been able to remove the infection. This drive and all other drives you have have save things on need to be formatted. Also if you have inserted this USB drive into other PCs, you have have infected those PCs. And if you copied even one executable file that was infected to any other PCs at any time, you may have infected that PC. If you copied any executables back on to your freshly formatted system, you are at risk. If you actually ran the executable, you are most likely reinfected.

    It is possible that your pictures are safe to copy, but under no circumstances can you trust any executable file. This includes any files to install programs that you have downloaded.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds