Please Help - BN.tmp & Iexplore.exe virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by AMKR, Feb 26, 2009.

  1. AMKR

    AMKR Private E-2

    Please help, I've been trying to get rid of these multiple viruses for over a week now. It all started when I uninstalled (I believe) AVG Anti-Virus, it seemed to release all the viruses in the quarentine out to play. I have tried to remove it using many different programs. I have one which is a series of .tmp files (mostly BN1.tmp, and BN2.tmp, sometimes just 2.tmp or 6.tmp, etc) which no matter how many times I delete them, or use various programs to get rid of them, they reappear when I reboot. The virus(es) will not let me install any new anti-virus programs (I tried Avira Anti Virus, Re-Installing AVG, and Avast AntiVirus), and even though it did let me install SUPERAntiSpyware program, it did seem to alter the installed info, because its just a random series of letters/numbers when I loaded it with a .exe, I have done all the requirements for assistance as seen in the Read Before Posting thread for Malware Removal. MGTools would not work for me, every time I attempted to use it, my computer would instantly restart, without any promt or warning. Just as soon as it loaded, boom, black screen, and BIOs window, restarting. I've tried many programs to get rid of my infections other than the required ones with logs attached, including SmitFraud Fix & Dr. Web Cure It (which seemed to actually catch alot of stuff, but didn't fix the main problems). I tried to use a program called "FixPolicies" which was supposed to help to fix the registry errors causing me not to be able to install any new programs, but again the viruses made my computer automatically restart without any prompt. Aswell as a program called SDFix which did the same thing, restarted my computer without a prompt. I also tried fixing the problem with a program called autoruns which came in a rar, but that did little to nothing. From what I can remember from the Dr. Web CureIt program, it seems that the virus has been corrupting almost all of my running processes and system files, mimicing them. I have about 15 instances of svchost.exe running at once, and a program masquerading as Internet Explorer, Iexplore.exe, of which multiple instances are running, and respawning after I end task them, even when I'm not using Internet Explorer (and even when I completely uninstalled internet explorer, and reinstalled the newest one).

    I have included the following logs for Spybot S&D, Malwarebytes AntiMalware, and SUPERAntiSpyware programs. I will follow with log for ComboFix (and my SmitFraud Fix log if you want it) when the thread is posted. I have uninstalled all old Java programs, and installed the lastest as told. I have been using ATF Cleaner and CCleaner after every cleaning using the various programs, and still to no avail...I'm out of clues as to what to do, please help me!! I can usually fix these things myself, but I've done everything I can possibly think of.

    Thank you for ANY help concerning this matter.
    -AMKR (of KILLMUSICK.com & Junction: OMEGA)
     

    Attached Files:

  2. AMKR

    AMKR Private E-2

    Heres the combo fix & smitfraud fix logs...
     

    Attached Files:

  3. AMKR

    AMKR Private E-2

    I'm not bumping this intentionally, I wanted to update it with some new logs. I used the a squared virus program, and it showed me that my SVChost.exe is infected...I no longer have a CD burner (cause the virus isnt allowing me to install any new firmware for it) or a floppy drive, and everytime I try to clean it with a squared windows needs to restart because svchost is a critical system component...I'm becoming extremely frustrated. I no longer have my windows disk either, so I can't burn a new boot disk or use a floppy and I can't delete this goddamned virus.

    Log attached.
     

    Attached Files:

  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    You need to disable TeaTimer as per the Read and Run First instructions,

    You also need to attach the C:\MGLogs.zip from running the C:\MGTools.exe.

    The MBAM log you attached indicates that nothing was fixed.

    Click Start > Control Panel > System > Hardware > Device Manager > View > Show Hidden Devices.

    * Scroll down to “Non-plug and Play Drivers” and click the plus icon to open those drivers.
    * Then search for TDSSserv.sys
    * Let me know if you find this or not.
    * If you do find it, right click on it, and select Disable. Do not try to uninstall it.
     
    Last edited: Feb 28, 2009

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds