Just got 'wormed' !!! on my home pc

Discussion in 'Malware Help (A Specialist Will Reply)' started by Adele, Mar 3, 2010.

  1. Adele

    Adele Private E-2

    Oh it is really awful! :cry
    I am on my ' Lovey-Buddy-My Baby-Laptop' right now because she is the only thing that is a pure as the driven snow around here.

    I really got a nasty dasterdly worm on my home pc and I can't do a thing with it.

    So far as I can tell I was looking up some calligraphy alphabets and all of a sudden it started showing up that I have this """big virus that will just almost kill me and take my first born and a few fingers'''' (well, it felt like that anyway). So I did click on the cute little box that said more or less that it would take all my worries away. 'What a Kick in the Mug'!!!!

    I cannot open anything. I feel like such a fool and a sucker! It will let me get to my yahoo home page, (if I'm lucky and feel real sneeky about it). But anything past that it just takes over and darkens my screen and puts up this box that has all of the shields and colors of them that at a glance you think you are dealing with the 'real' people.

    Oh I could just kick myself in the deriere more than once for even getting my big ''puter into this perdicament!

    What it is, is ... Antivir Resident Shield

    The file it is in, ( I think...maybe) is ... C:\Program Files\Yahoo\Companion\Installs\cpn11\ytbb. exe

    Description is... W32.Gosys
    and it says that it is a worm.

    I have 4 or 5 yr old HP Pavilion Media Center Edition
    with Windows XP Home

    I also have McAfee

    You folks here at Major Geeks have never let me down. And I know for sure that I can always turn to Major Geeks when ever my internet world has fallen down around me.

    I have the utmost faith in all of you here and am asking ....again...if you could possibly dig me out of this one...

    And I did take a real hard gander at the 'Cleaning a Comprimised System' but I am so ... afraid that I'll mess something up on it more.
    Sure am glad thatall of you here are here to help! And Really know what the heck your doing.

    Thank you so much, I would be totally lost without ya'll. I don't even want to think about what I would do without Major Geeks.

    Thanks!!
    Adele
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Download and save the below to your PC (save it anywhere you can find it. The Desktop is fine). Then double click on it to run it.

    AVPFind.bat

    It should take a couple minutes to run. You will see a black command prompt window while it is running and it should close when it is finished. Once it finishes, attach the avplog.txt file that is will hopefully be created on your Desktop as long as the malware does not block the batch file from running. (See: HOW TO: Attach Items To Your Post)

    Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.

    There are 4 different versions. If one of them won't run then download and try to run the other one.

    Vista and Win7 users need to right click and choose Run as Administrator


    You only need to get one of them to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

    1. Rkill.exe
    2. Rkill.com
    3. Rkill.scr
    4. Rkill.pif


    * Double-click on the Rkill desktop icon to run the tool.
    * If using Vista or Windows 7 right-click on it and choose Run As Administrator.
    * A black DOS box will briefly flash and then disappear. This is normal and indicates the tool ran successfully.
    * If not, delete the file, then download and use the one provided in Link 2.
    * If it does not work, repeat the process and attempt to use one of the remaining links until the tool runs.
    * Do not reboot until instructed.
    * If the tool does not run from any of the links provided, please let me know.
    Once you've gotten one of them to run then try to immediately run the following.

    Now download and Run exeHelper from Raktor

    • Please download exeHelper to your desktop.
    • Double-click on exeHelper.com to run the fix.
    • A black window should pop up, press any key to close once the fix is completed.
    • A log file named log.txt will be created in the directory where you ran exeHelper.com
    • Attach the log.txt file to your next message.

    Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

    If you already have them installed, be sure to update Malwarebytes and SUPERAntiSpyware before the scan!

    Now run this: Using Malwarebytes Anti-Malware

    Now run this: SUPERAntiSpyware - running & getting a log

    Now run this: Using MGtools


    Now you need to attach (See: HOW TO: Attach Items To Your Post ) the below logs created while running the above scans

    • exeHelper log
    • Malwarebytes Anti-Malware log
    • MGlogs.zip - normally it is C:\MGlogs.zip - only attach this log from MGtools.exe DO NOT attach any logs seen in the MGtools folder.
     
  3. Adele

    Adele Private E-2

    Hi Tim,
    I can't thank you enough for replying so fast and with all of the things that I need to do.

    Unfortunately I can't tell you how well it worked because my hubby won't let me near it.

    I home hoping that he either gets it back up to par, or finally gives me the go ahead to do what I gotta do..

    Please don't feel that you have answered me in vain. And as soon as I get my chance I will follow the directions and all that you were kind enough to share with me. And let you know right away how it went. So please, don't think that your help was all in vain.

    Hopefully I won't be starting a thread asking how to fix a bigger problem. hehe

    So thank you very much!
    adele
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Not a problem. What ever works!! :)
     
  5. Adele

    Adele Private E-2

    Hey Tim!
    It took me awhile for him to do what all he was going to do. And somehow he did manage to get rid of that blue and yellow Antivir Shield that was stuck on my QuickLaunch, and with that he did manage to get rid of the things that it was causing.
    But...only to have it change to something else that would block anything that I tried to get past my home page.
    I let him reap the glory of getting rid of what he did and didn't mention the other that took it's place.
    Oh the married life. Our 11th anniversay was a few days ago and we are just as madly in love as we were the day we married. It's just one of those little things that ya gotta love about each other... well enough of the gooey sap. haha oops.
    Anyway, I figured out a way to finagle my way here for the downloads and everything went to smooth. But the only thing that I didn't download was the Using MGTools. I was trying to do all that I did do as fast as my little fingers could fly.
    Could you possible tell me more about Using MGTools?
    It was like sliding down a real icy driveway with old sneakers with no tread. Oh, and of course not falling.
    So kudos to ya Tim!!!
    I couldn't have done it without ya!!!!!
    And you made my day!!!:celebrate
    Thanks again!!!
    adele
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    MGTools.exe should be downloaded to your root drive....as in C:\MBTools.exe. When run, it will produce a set of logs here: C:\MGLogs.zip. The logs inside the zip will provide me with a lot of information that will help me find and remove any infections. Is this what you wanted to know? Where are we with this system? Is it still infected?


    PS: Happy Anniversary.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds