E-Card.exe Virus and Stuck in safe mode

Discussion in 'Malware Help (A Specialist Will Reply)' started by MsPayne, Aug 14, 2008.

  1. MsPayne

    MsPayne Private E-2

    Hi,

    I have read the readme and downloaded all tools. As I am stuck in safe mode SAS will not work no matter what I try.
    I opened an email with the ecard.exe virus and the blue screen of death happened. I now cannot log on in normal mode.
    I cannot change the system so I can see any hidden files. The system did log back on in normal mode and my desk top had changed to a blue one that said spy ware had been detected.
    I am running windows vista.
    I really need some help and would really appreciate any support.
    I have uploaded MB log.
    Thank you so much in advance.
    I am at present inishing my final dissertation and would really appreciate any support asap
     

    Attached Files:

    • mb.txt
      File size:
      2.2 KB
      Views:
      7
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    First you need to re-run MalwareBytes and have it fix/quarantine everything it finds.

    Then Please follow the instructions in the below link and attach the requested logs when you finish these instructions.


    If something does not run, write down the info to explain to us later but keep on going.

    Do not assume that because one step does not work that they all will not.


    READ & RUN ME FIRST. Malware Removal Guide


    Note:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode. You can running steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    Starting your computer in Safe mode

    2. If you have problems downloading on the problem PC, download the tools on another PC and burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
     
  3. MsPayne

    MsPayne Private E-2

    Below are the logs from Malaware and combofix. I cannot upload the MG tools log as it exceeds forum size limit. Superantispyware will not work as the windows installer is unavailable in safe mode.
    Thanks
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you trying to upload C:\MGLogs.zip .....it is not that big a file. What exactly is happening?

    In the meantime:

    * Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    o If it is not on your Desktop, the below will not work.
    * Open Notepad and copy/paste the text in the below code box into it (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    KILLALL::
    
    
    Drivers::
    trpsorss
    
    File::
    C:\Windows\system32\drivers\trpsorss.sys
    
    
    * Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    * At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    * You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    * Now use your mouse to drag CFscript.txt on top of ComboFix.exe
    * Follow the prompts.
    * When it finishes, a log will be produced named c:\combofix.txt
    * I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.
     
  5. MsPayne

    MsPayne Private E-2

    Hello,

    Here are both logs. I am now back on the normal desktop, although it is very slow. Where do we go from here?
    I attach both mg log and combofixlog
    Thanks
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Are you getting errors when you run MGTools? What exactly is happening when you double clicking on the C:\MGtools\GetLogs.bat file?
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds