Downloader Virus help! Hijack log attached

Discussion in 'Malware Help (A Specialist Will Reply)' started by Lauradorable24, Aug 20, 2006.

  1. Lauradorable24

    Lauradorable24 Private E-2

    Hi,
    I'm new to this forum, and I need some help! I have a 2000 Dell Dimension Desktop computer, Windows XP. I have a symantec antivirus program (is it a program or software?) that alerted me that I have a Downloader Virus. I looked it up online from another computer and followed the instructions on a MajorGeeks forum to use HijackThis, and I created the log that was in the directions. So now I'm posting the log and hoping someone can help me!!
    I'm not able to get on the internet with my infected computer so I have a laptop set up next my computer, hoping to troubleshoot through this forum. I would appreciate any help, comments, feedback. I know a little about computers, but not enough to fix this nasty virus. Thanks in advance :)

    Lauren
     

    Attached Files:

  2. Shadow_Puter_Dude

    Shadow_Puter_Dude MG Authorized Malware Fighter

    Welcome to MajorGeeks.com!

    Please follow our standard cleaning procedures which are necessary for us to provide you support. Also there are steps included for installing, running, and posting HijackThis logs as attachments.

    - Run ALL the steps in this Sticky thread READ & RUN ME FIRST Before Asking for Support
    • Make sure you check version numbers and get all updates.
    After doing ALL of the above you still have a problem make sure you have booted to normal mode and run the steps in the below link to properly use HijackThis:

    Downloading, Installing, and Running HijackThis

    Make sure you also rename HijackThis.exe as suggested in the procedures. Use analyse.exe for the new name. This is very important due to some new infections going around.

    When you return to make your next post, make sure you attach the following logs and that you have run these scans in the following order too:
    • runkeys.txt - the log from GetRunKey.bat
    • newfiles.txt - the log from ShowNew.bat
    • CounterSpy - ONLY IF you were not able to run Windows Defender
    • Bitdefender - from step 6
    • Panda Scan - from step 6
    • HijackThis
     
  3. Lauradorable24

    Lauradorable24 Private E-2

    Thanks for the reply, I just want to make sure I've got this right... I should follow the steps (1-6) on "Read & Run Me First", before I post my hijackthis log? I just want to make sure I'm doing the right thing before I do it, and post it.

    Thanks,
    Lauren
     
  4. Lauradorable24

    Lauradorable24 Private E-2

    Please help me I'm going crazy! I've been dilagently following the "Read Me First" directions and I've come to a speed bump. I downloaded the Windows Malicious Software Removal, but I can't seem to open it. Whenever I try I get the window popping up saying to choose a program to open it with, I have no internet connection due to the virus, so the only other choice is to manually choose a program. I have no idea how to open it. It seems to be a .pf file, whatever that means. I've come so far, please help me open this program so I can continue with the directions. Thanks!:eek:

    Lauren
     
  5. Lauradorable24

    Lauradorable24 Private E-2

    Stuck on Step 5 please help ASAP!!

    Hi,
    I'm trying to follow the "Read & Run Me First" steps and I'm stuck! Please help me! I'm on step 5, I downloaded the Windows Malicious Software Removal, but I can't seem to open it. It's located in C drive Windows folder, in a folder called Prefetch. The Windows Malicious Software Removal Tool is saved in the folder as "WINDOWS-KB890830-V1.19. PF File". When I try to click on it to open it I get a pop-up saying: "Windows cannot open this file: WINDOWS-KB890830-V1.19.EXE-1759D200.pf To open this file Windows needs to know what program created it." I am not able to go online to look it up and the other choice is to manually select a program. What program do I use to open it? Did I do something wrong? I'm stuck on this step and it's very frustrating, I thought I was doing so well, and now I'm going nuts trying to figure out what to do! I've come so far, please help me open this program so I can continue with the directions. You guys have been very helpful. Thanks! I appreciate it.


    Lauren
     
  6. Lauradorable24

    Lauradorable24 Private E-2

    Sorry I posted this last one as a reply, instead of on the main forum. It's posted twice now, sorry about that!

    Lauren
     
  7. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Hi Lauren

    No probs.. I deleted the other one ;)


    Try downloading again but this time before you download, create a folder on your C drive called C:\Spyware Tools then goto the download location of the MSRT tool http://www.majorgeeks.com/Microsoft_Malicious_Software_Removal_Tool_d4471.html and when you click to download the file choose Save, you will se a Save As box come up... then browse for that created folder using the save in dropdown menu, once you have found the C:\Spyware Tools folder and double clicked it to open it, click Save and hopefully the MS Malicious Software Tools will be saved in that folder then continue with the instructions.

    Hope it works :)
     
  8. Lauradorable24

    Lauradorable24 Private E-2

    Sorry to be a pain, but I can't download it from the computer with a virus, so I'm downloading it to my other computer and saving it to my flash drive. When I try right click on it and save it in the folder I created (on the virus computer) that's not an option. I created the folder but I can't save it there. If I double click on the Windows Malicious tool it just installs it, and I don't know where. Am I doing something wrong?

    Lauren
     
  9. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Your not a pain at all, its just sometimes a fault of both of us not being infront of the same PC.. can take a bit of time to get on same page and understand what we are both trying to do.... we will get their in the end :)

    Ok if its downloaded ok on the other PC and then copied to the flash drive ok then right click the MS Tool and choose Copy then open the folder created on the infected PC and right click and paste, then continue with the instructions as the tool is best run in Safe Mode.

    Yes you double click it and it looks like its installing but actually its scanning your PC, you should gain at the end a list like this IF you click "view detailed results of scan"

    http://img245.imageshack.us/img245/6536/untitledsm9.jpg
     
    Last edited: Aug 22, 2006
  10. Lauradorable24

    Lauradorable24 Private E-2

    thanks for your help, i figured it out after I emailed you. I didn't click on "view detailed report of the scan" because I did the scan before I got your email. Was I supposed, is that ok if I didn't? I'm onto CounterSpy now, I think I'm back on the right track :)
    Lauren
     
  11. Lauradorable24

    Lauradorable24 Private E-2

    Here I go with another question...I'm reading ahead and see that I have to use BitDefender. I've been downloading these things to a different computer then saving them to a flash drive and installing them on my computer with a virus. I don't have internet access due to the virus, so I won't be able to use BitDefender. Is is possible my internet will be working now since all of the cleaning? If not, what should I do for this step because I can't save BitDefender to my flash drive?

    Lauren
     
  12. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    No that was ok to click View Results on the MSRT scan as we would have needed to know if it found anything, but if it didnt then your ok on those malware items it was scanning for.

    Bitdefender and Panda scan are both online scans and would need to be run with internet connection ( sadly no save to flash drive ), its worth trying as you should be in Safe Mode with networking and once upto that part for the online scans, yes do try but do let is know which scans or software wont install or run and any reasons why.

    Seems like your doing fine, just contnue as best as you can and attach any logs you could run at the end.
     
  13. Lauradorable24

    Lauradorable24 Private E-2

    You have been incredibly helpful! Thanks for being so patient, this is the best internet resource I've ever found. I'm telling EVERYONE I know about majorgeeks!! I'll let you know how I make out with the rest of the process once I finish, I've been doing this for 2 days now :)

    Lauren
     
  14. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Great, my pleasure ;)

    Once you have the procedures and logs attached the guys in this part of the forum who deal with malware are VERY good at clearing it, so good luck :)

    David
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds