Not sure if FBI virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by monita, Jul 3, 2012.

  1. monita

    monita Private E-2

    Good morning Dear Majorgeeks,

    When user turned computer on his picture was on the screen, said something about FBI and to pay $100, it could be done at Walmart and other 2 stores. The user turned the computer off and then on again. All his icons had disappeared. After I ran in safe mode the programs you recommend, the icons came back on.

    I ran RogueKiller, Malwarebytes, HitmanPro and MGtools.
    I am attaching the logs.
    I would appreciate your taking a look at them and tell me if this computer is clean.
    Thank you so much!
    monita
     

    Attached Files:

  2. thisisu

    thisisu Malware Consultant

    Hello monita :)

    http://img850.imageshack.us/img850/4746/programsandfeatureswin7.gif From Programs and Features (via Control Panel), please uninstall the below:
    • Ask Toolbar
    • Java(TM) 6 Update 30 <- Outdated

    Delete the follow items using Windows Explorer:
    • C:\Program Files (x86)\Ask.com <- Folder
    • C:\ProgramData\-koo7TMqLb9Cdch <- File
    • C:\ProgramData\-koo7TMqLb9Cdchr <- File

    http://img205.imageshack.us/img205/4783/regeditb.gif Open Notepad and copy everything in the code box below into it.
    Code:
    REGEDIT4
    
    [-HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{CFE6B1AA-C553-4D89-A739-3627F73A4849}]
    [-HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}]
    • File -> Save As -> Save as type: "All Files" -> File Name: fixme.reg > Save.
    Now merge this into the registry by double-clicking it.
    Let me know if the merge was successful or not.

    __

    http://img195.imageshack.us/img195/9049/javaz.gif Now install the current version of Sun Java from: here

    __

    Let me know if any other problems remain after you have completed the above steps.
     
  3. monita

    monita Private E-2

    Dear Thisisu,

    Thank you for yours instructions. Everything was successful. There are 2 things that I would like to mention to you.
    One is I'm getting a RunDLL error message which reads as follows:
    "There was a problem starting c:\users\alan\appdata\local\temp\o_ou_I.exe
    The specified module could not be found"

    The other one is that the user seem to be missing some of his favorites since before and everytime he is adding one he gets the message that it is already there but it doesn't show.

    One again, Thank you. Your help is very much appreciate it.
     
  4. thisisu

    thisisu Malware Consultant

    http://img18.imageshack.us/img18/6738/autoruns.gif Download Autoruns to your desktop.
    • See the download links under this icon: http://forums.majorgeeks.com/chaslang/images/MGDownloadLoc.gif
    • Create a folder on your desktop called "autoruns"
    • Extract the contents of the Autoruns.zip file into the autoruns folder you created.
    • Now open this folder by double-clicking it.
    • Now double-click autoruns.exe to run. (Vista and Win7 right-click and select Run as administrator)
      Note: Autoruns will automatically start scanning your system for autorun entries. This process is typically finished within 15 seconds.
    • When you see Ready at the bottom-left corner of the Autoruns program, the scan is complete.
    • Now click File > Save
    • Change the Save as type: to Text (*.txt)
    • Save AutoRuns.txt to your desktop or another location you can easily access it.
    • Attach AutoRuns.txt to your next message. (How to attach items to your post)
     
  5. monita

    monita Private E-2

    Dear Thisisu,

    Attached please find the autorun.txt.

    Once again, my sincere thanks.
    monita
     

    Attached Files:

  6. thisisu

    thisisu Malware Consultant

    http://img805.imageshack.us/img805/9659/rktigzy.gif Open RogueKiller.

    Double-click RogueKiller.exe to run. (Vista/7 right-click and select Run as Administrator)
    When it opens, press the Fix Shortcuts button.
    When it is finished, there will be a log on your desktop called: RKreport[2].txt
    Attach RKreport[3].txt to your next message. (How to attach)

    __

    http://img825.imageshack.us/img825/2648/hjt.gif Run C:\MGtools\analyse.exe by double-clicking it (Vista/7 right-click and select Run as Administrator)
    Shut down your protection software now (antivirus, antispyware...etc) to avoid possible conflicts.
    Choose "Do a system scan only" and select the following lines but do not click fix until you exit all explorer windows and all browser sessions including the one you are reading in right now:

    O4 - Startup: ctfmon.lnk = C:\Windows\System32\rundll32.exe

    After clicking Fix, exit out of Trend Micro HiJackThis - v2.0.4

    __

    Now reboot your computer and let me know which problems remain, if any.
     
  7. monita

    monita Private E-2

    Dear Thisisu,

    I'm sorry, but I don't find MGtools\analize.exe. All I see is MGtools.exe
     
  8. thisisu

    thisisu Malware Consultant

    Do you see this folder? C:\MGtools
     
  9. monita

    monita Private E-2

    Dear Thisisu,

    I finally found the MGtools\analyze.exe. I ran it. Reboot the computer and the error message did not come up. Also, I believe his favorites are back.

    Attached is the RogueKiller log. His desktop has 2 icons called "desktop.ini" is that normal?

    I have no words to express my appreciation and respect I have for majorgeeks.

    thanks,
    monita
     

    Attached Files:

  10. thisisu

    thisisu Malware Consultant

    Yes according to the RogueKiller log it restored the attributes of 22 favorites. ;)

    Normal. They will go away once you run the final steps below.

    You're very welcome :)

    __

    If you are not having any other malware related problems, it is time to do our final steps:
    • Any programs we had you download and/or install can be removed at this time.
    • If we had you download and run ComboFix, here is how to uninstall it:
      • Press and hold the Windows key http://i1106.photobucket.com/albums/h363/debojyotidas/Windows_Logo_key.gif and then press the letter R on your keyboard.
      • This opens the Run dialog box.
      • Copy and paste the below text inside the text-field:
        • "%userprofile%\desktop\ComboFix" /uninstall
      • Now press ENTER
      • ComboFix will extract its files one last time and you should receive a notification that ComboFix has been uninstalled shortly after.
    • You can re-enable your Disk Emulation software at this time via DeFogger.
    • If we had you create or download a registry patch or "fix" script, these can be deleted at this time.
    • Go into the C:\MGtools folder and run the MGclean.bat file to remove additional traces of our tools.
    • Now we will toggle System Restore to remove any infected system restore points.
    • Lastly, here is a guide to protect you from future infections: How to Protect yourself from malware!
    • Be safe :)
     
  11. monita

    monita Private E-2

    Dear Thisisu,

    My most sincere thanks for your help.

    monita
     
  12. thisisu

    thisisu Malware Consultant

    My pleasure, monita.
    Be safe :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds