Ircbots Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by mquelch, Oct 17, 2011.

  1. mquelch

    mquelch Private E-2

    Hi,

    I have two computer at home a laptop (this) and a desktop. I am also using a router. My Internet provider called and left a voice mail that I have a virus on the computer (Ircbots), and if I don't clean the computer in 24 hours they will disconnect my internet access.

    I know I had a problem on the laptop, and I've tried several cleaning methods. I know the problem was not completely fixed, but I thought I had some time to deal with it this coming weekend. Now I've run out of time and I need your help.

    I've attached some logs
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to attach the log from MGtools that was requested.
     
  3. mquelch

    mquelch Private E-2

    Hi,

    Here is the log.
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Goto the below link and follow the instructions for running TDSSKiller from Kaspersky
    Now please also download MBRCheck to your desktop.

    See the download links under this icon http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Double click MBRCheck.exe to run (vista and Win 7 right click and select Run as Administrator)
    • It will show a Black screen with some information that will contain either the below line if no problem is found:
      • Done! Press ENTER to exit...
    • Or you will see more information like below if a problem is found:
      • Found non-standard or infected MBR.
      • Enter 'Y' and hit ENTER for more options, or 'N' to exit:
    • Either way, just choose to exit the program at this point since we want to see only the scan results to begin with.
    • MBRCheck will create a log named similar to MBRCheck_07.16.10_00.32.33.txt which is random based on date and time.
    • Attach this log to your next message. (See: HOW TO: Attach Items To Your Post )
     
  5. mquelch

    mquelch Private E-2

    Hi,

    I ran both programs and TDSSkiller said no viruses.
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This PC does not appear to be having malware problems. All of your logs are clean.


    Since you do not appear to be having malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 oof the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista or Win 7, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. After doing the above, you should work thru the below link:
     
  7. mquelch

    mquelch Private E-2

    Thanks Chaslang, I appreciate your help. What viruses did you find on the computer?
    Do you have any idea how we got them? We are careful on which websites we visit, and we don't open emails we are not familiar with. We were using Kaspersky Internet Security when I noticed something was wrong, so I was very disappointed Kaspersky did not protect us as it should. Any we changed to Norton two weeks ago when Kaspersky expired, and Norton did a scan before installation and it did not identify a problem. However I did notice something was still wrong.

    My question is what can we do different, or what should we be doing that we are not?

    Thanks again.
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.
    As stated in my last message.
    See the link in the last step of my last message.;)

    Also do not plug that possibly infected external drive from your other PC into this PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds