Problem with Virus infection

Discussion in 'Malware Help (A Specialist Will Reply)' started by mongooseba, May 22, 2009.

  1. mongooseba

    mongooseba Corporal

    :-oHi All,

    I'm not sure that I have removed all the viruses from my computer. Some one accidently surfed the computer and downloaded some virus. The computer would periodically freeze and a continuous beep would occur. Kindly check my logs and advise what to do next. I have also removed the old Javas as well. Thanks and will wait for your advise.

    Mongooseba:-o
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Hi there and welcome. Currently reviewing your logs and will get back to you with a set of instructions as soon as possible. Thanks for your patience.

    Kes
     
  3. mongooseba

    mongooseba Corporal

    Hi, Kes,

    Thanks for the reply. Looking forward to your help. I'm concerned about the freeze with a continuous beep after surfing or working on the computer for about 15 to 30 minutes. This often happens when the internet is on.

    Mongoosebarolleyes
     
  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    GMER's MBR.exe
    • Double click on the MBR.exe file to run it.
    • A log will be produced & saved to the desktop, called MBR.log.
    • Attach this log to your next message.

    Now delete the current mbr.log file and then run the below instructions.
    Click Start > Run and copy & paste the following text in the code box into the Run box and then click OK. You must copy and paste or type in this exactly. The quotes must be exactly as shown and there is a space before the -f
    Code:
    
         "%userprofile%\desktop\mbr.exe" -f
    
    Now double click on the mbr.exe file and attach the new mbr.log




    1. Tidy up this desktop a little...

    A cluttered Desktop is malware's playground and it can also cause performance degradation.

    2. Please go to Add/Remove programs and uninstall the following old versions of Java:

    • J2SE Runtime Environment 5.0 Update 6
    • J2SE Runtime Environment 5.0 Update 9


    3. Please disable all anti-virus and anti-spyware programs while we do the following (re-enable when you are finished):

    Run C:\MGtools\analyse.exe by double clicking on it (Note: if using Vista, don't double click, use right click and select Run As Administrator). This is really HijackThis (select Do a system scan only) and select the following lines but DO NOT CLICK FIX until you exit all browser sessions including the one you are reading in right now:

    After clicking Fix exit HJT.


    4. Now we need to use ComboFix.
    • Make sure that combofix.exe that you downloaded while doing the READ & RUN ME is on your Desktop but Do not run it!
    • If it is not on your Desktop, the below will not work.
    • Open Notepad and copy/paste the text in the below code box into it
    (make sure you scroll all the way down in the code box to get all lines selected ):
    Code:
    
    KILLALL::
    
    File::
    C:\Documents and Settings\PD-Reception2\usrusmt2.tmp
    C:\WINDOWS\PEV.exe
    C:\WINDOWS\Temp\rg4sfay
    C:\WINDOWS\Temp\ydf8dk 
    
    
    
    
    • Save the above as CFscript.txt and make sure you save it to the same location (should be on your Desktop) as ComboFix.exe
    • At this point, you MUST EXIT ALL BROWSERS NOW before continuing!
    • You should have both the ComboFix.exe and CFScript.txt icons on your Desktop.
    • Now use your mouse to drag CFscript.txt on top of ComboFix.exe

      http://farm4.static.flickr.com/3014/3035535531_512f04c6a2_o.gif

    • Follow the prompts.
    • When it finishes, a log will be produced named c:\combofix.txt
    • I will ask for this log below

    Note:

    Do not mouseclick combofix's window while it is running. That may cause it to stall.


    5. Also delete all files in the below folders except ones from the current date (Windows will not let you delete the files from the current day).

    6. Now reboot your machine and install the most current and up to date version of Java available here at the below link:

    Java Runtime 6

    7. Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this and also attach the log from Avenger or Combofix

    8. Let us know of any problems you may have encountered with the above instructions and also let me know how things are running now.
     
  5. mongooseba

    mongooseba Corporal

    Hi, Kestrel13!,

    Thanks for the reply. Did all as instructed.

    1. MBR.exe: downloaded to desktop and activated system with specific text. However, I do not believe it worked. Please see log before and after. A virus was detected in the display
    2. Desktop still not tidied up but will do so after when my staff is back\
    3. Removed JAVA and reinstalled new JAVA
    4. Removed the two entries on HijackThis but kept the Invisalign b/c that is required for the program to work
    5. Combofix activated using Killall
    6. Files in c:|windows\tmp deleted except for current files
    7. Current MGTool retrieved

    Do I need to reactivate the MBR.exe? The MBR.exe was placed on my desktop. Please advise.

    Mongooseba:-o
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Please reboot with the XP CD and get into the recovery console....once there, type fixmbr and then hit enter.

    Next...

    Now run the C:\MGtools\GetLogs.bat file by double clicking on it. Then attach the new C:\MGlogs.zip file that will be created by running this.
     
  7. mongooseba

    mongooseba Corporal

    :-oHow am I suppose to use the XP disc? Am I suppose to reset the boot sequence? Is the first screen on recovery mode? Please advise with detail instructions. Thanks.

    Mongooseba:-o
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    OK my fault... You do not need to use a CD. You already have the Recovery Console installed from the procedure with ComboFix and can therefore follow Option 1 of this:

    Option 1: If you have already installed the Recovery Console
     
  9. mongooseba

    mongooseba Corporal

    Kestrel13!,

    Got to the recovery console and typed "fixmbr'. Windows recreated new mbr. Ran the MG log. Kindly see attached. Waiting for further instructions.

    Mongooseba
     

    Attached Files:

  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Certainly will :) It's late for me now but I will get to you at some point tomorrow rest assured.

    Kes
     
  11. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Also delete all files in the below bold folders except ones from the current date (Windows will not let you delete the files from the current day).

    Let me know how everything is running and if you are not having any other malware related problems then it will be time for me to give you final steps.

    Thanks
    Kes
     
  12. mongooseba

    mongooseba Corporal

    Kestrel13!,

    Did as instructed by removing the following:

    C:\WINDOWS\Temp
    C:\Documents and Settings\PD-Reception2\Local Settings\TEMP

    So far the computer has not crashed as usual. Will try out again tomorrow. What should I do if things work out? Thanks.

    mongooseba:p
     
  13. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommed you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /u
        • Notes: The space between the combofix" and the /u, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
      • Delete the C:\combofix folder from combofix (if it exists)
    3. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    4. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    5. Go to add/remove programs and uninstall HijackThis.
    6. You can delete the C:\MGtools folder and the C:\MGtools.exe file. You can also delete the C:\MGlogs.zip
    7. If you are running Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning steps in the READ ME for your Window version and see the steps to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    8. After doing the above, you should work thru the below link:
     
  14. mongooseba

    mongooseba Corporal

    Dear Kestrel13!,

    Thanks for all your help. The computer is fine and responding well. :-D:-D:-D

    Mongooseba
     
  15. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Glad to hear it! and you're welcome! :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds