Help with Virus

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Monika1223, Jan 29, 2012.

  1. Monika1223

    Monika1223 Private E-2

    Hello,
    I have run all the programs that will run plus unhide. Everything seems normal but i have no System Tools it says "Internet Explorer (No Add Ons) and it will not run root repeal it comes up with error "Error_Invalid PE Image Found". All logs are attached. I also ran Malware twice because it did not update (no internet hooked up), second run did not find anything.Thanks forthe help in advance.

    Monika
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hi and welcome to Major Geeks, Monika1223!

    http://img196.imageshack.us/img196/3557/tdsskiller.gif I want you to read and follow these instructions: TDSSKiller - How to run


    http://img707.imageshack.us/img707/6703/generalxpicon.gif Please download MBRCheck by clicking here and save it to your desktop.

    • Double-click on the file to run it. (Vista/7 right-click and select Run as Administrator)
    • A window will open on your desktop.
    • If an unknown bootcode is found you will have further options available to you, at this time press N then press Enter twice.
    • If nothing unusual is found just press Enter.
    • A .txt file named MBRCheck_mm.dd.yy_hh.mm.txt should appear on your desktop.
    • Attach this file to your next message. (How to attach)
     
  3. Monika1223

    Monika1223 Private E-2

    Thanks Thisisu,
    I have run both programs have not noticed any change, still do not have system tools.

    Thanks
    Monika
     

    Attached Files:

  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    This may not be a malware problem ( However you do have malware to fix ). Sounds to me like you may be using Windows Explorer to look at folders. The below folder is where you would see the Internet Explorer (No Add Ons) you commented on. ( replace USERACCOUNT with your user account name )

    C:\Documents and Settings\USERACCOUNT\Start Menu\Programs\Accessories\System Tools

    Whereas to see the rest of the System Tools, you would need to look in the All Users account

    C:\Documents and Settings\All Users\Start Menu\Programs\Accessories\System Tools


    What is list under All Programs -> Accessories -> System Tools is a combination of the above two mentioned folders.
     
  5. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    After checking a little deeper into your logs, I see you have signifcant malware problem that I regret to have to inform you about. You have Virut infection. Below is one of our standard posts about Virut.

    The most effective and reliable method to remove Virut is by a total clean reinstall.
     
  6. Monika1223

    Monika1223 Private E-2

    Hello Chaslang,
    Well I went to look at those folders "Useraccount" had the IE Icon mentioned and the all users had nothing in it. Just letting you know.
    I have been lurking and using your malware sources for a long time and this was the first time I had to make a post, now I see why. I will do a clean install, anything special I need to do?

    Thanks for everything
    Monika
     
  7. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Just a format and reinstall of Windows ( I assume you have your Windows XP cd to reinstall from ) and then reinstall your protection software from either new downloads or from an original CD. DO NOT use any executable files that you have saved anywhere since this infection. Virut can spread itself to all executable files ( every installer file you have downloaded and saved could be infected which is why you need new ones after the format ). If you reload even just one infected file, the whole problem will start again.

    Note: Any removable drives you have plugged into this infected PC could be carrying the infection and if these removable drives were plugged into any other PCs, those PCs could be infected now.
     
  8. Monika1223

    Monika1223 Private E-2

    This does not sound fun....
    I did move a thumb drive between computers when I was working on it. What should I do? Also what about over a network will it move that way, because the infected computer has been on my home network and a work network, and the computer that i used the thumb drives (to get programs for infected computer) was on another work network. I hope and pray it has not infected my network. Please Help

    Thanks
    Monika
     
  9. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You're welcome.

    Run a FULL antivirus scan on all computers ( I assume they all have an antivirus program installed ). Also run at least one online scanner AFTER running the normal antivirus scan. You can use the below tool from ESET but we don't need the logs from all of the computers. You just need to scan to see if anything is found to be fixed.

    Using ESET's Online Scanner

    Computers on a network would only be susceptible if you have files/folders/drives being shared between computers on the network. If they are being shared, then were/are at risk. This does not mean for sure they are infected. It just means there is a chance that they are. The same applies to copy files to and from the thumb drive and inserting in other PCs. Depending on the contents of the thumb drive and whether you actually ran anything from it, it could increase the probability of it being infected.
     
  10. Monika1223

    Monika1223 Private E-2

    I am sorry for jumping the gun, but I did not wait for an answer so I started doing the READ and Run Me first and removed my antivrius (rising). Once I read your post I did the ESET scan and will post all the logs. Superantispyware's logs just say the date and version ran so I am not going to post those. When I ran the root repeal I got the same error on this laptop as I did with the infected computer "Error_Invalid PE Image Found". Please look over logs to make sure I dont have that rotten little virus "virut".
    Also I noticed when I came back to reply this thread was locked, I then used my other computer to look up information so I can post correctly and it said it was open not sure if it means anything just something I noticed.

    Again sorry for jumping the gun chaslang

    Monika
     

    Attached Files:

  11. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    We really don't like having logs from multiple computers posted in one thread as it tends to make the thread hard to follow and to separate one computer from another.

    But the logs you posted are the least important. MGlogs.zip from MGtools would be the most useful to see if files have been getting changed by Virut. Also you need to run a full scan with your own antivirus program to see if it reports anything, but it appears you don't even have one installed which is extremely dangerous especially in light of having a Virut infection on another PC.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds