trojan.rbec fixed but other virus still present

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Beardmaster, Mar 30, 2012.

  1. Beardmaster

    Beardmaster Private E-2

    My business partners computer was infected with a virus about a week and a half to two weeks ago when he clicked on a link in an email that appeared to be a legit invoice or balance statement from Fedex or USPS (don't know forsure just going based on what he remembers).

    When I ran AVG it found a number of problems which it was able to clear off but was not able to remove the .rbec issue because it was attatched to a whitelisted system file.

    I found this forum searching for solutions and have followed the READ & RUN ME FIRST proceedures. A few things to note that I may have not done completly correct during the process.

    1. Ran superantispyware but couldn't remember if I asked it to fix the problems before I ran the log. Pretty sure I did but not 100%

    2. Was running combofix but instead of it going through the whole process to logs it outputed to the command prompt in the windows with the blue background and stopped processing anything. I closed the command prompt manually, ran explorer from the task manager, rebooted and then re ran combofix.

    3. The instructions directed to download all the programs first before running them. I downloaded the AVG remover as requested but didn't see instructions to run it at any point (other than disabling all antivirus software I suppose, my bad) until I was already running combofix the 2nd time around (after having to close it due to going to the command prompt line instead of going through it's complete process) I rebooted between the 1st and 2nd time I ran combofix and AVG must have started again on the reboot. During the 2nd running of combo fix the AVG conflict came up so I cancelled the combofix fun and ran the avg removed and rebooted again upon reboot combofix was run for the 3rd time and it when through it's completey cycle down to the log output.

    4. Ran superantispyware again after the whole process and still received threat warnings. I DID NOT ask superantispyware to quarantine or heal these problems and they should be listed in the 2nd Superantispyware log that I've included on the attatchments
     

    Attached Files:

  2. Beardmaster

    Beardmaster Private E-2

    additional logs
     

    Attached Files:

  3. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    What issues are you currently having. It would be good if you would attach the log from AVG so we can see what it is complaining about.
     
  4. Beardmaster

    Beardmaster Private E-2

    AVG has been completely removed from my computer due to the conflict with combofix. I checked in the Application Data folder and didn't see any AVG logs left in there.

    The log already attatched from SuperAntiSpyware that is dated on Mar 29th should have the current virus complaints in it.

    My primary problem that is affecting the computer is that it won't allow me to connect it to my my server computer in my work network.
     
  5. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    I wasn't seeing any additional malware in your logs. I suggest you post in the software forum for help with your server issues.
     
  6. Beardmaster

    Beardmaster Private E-2

    Just ran SuperAnti again.

    New log and Screenshot attatched. I have again not asked it to quarantine or remove any of the three issues.
     

    Attached Files:

  7. Beardmaster

    Beardmaster Private E-2

    lets try that screenshot again
     

    Attached Files:

  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Why are you not having it fix what if finds?
     
  9. Beardmaster

    Beardmaster Private E-2

    As quoted from Read me instructions

    "Step 3: Do You Still Have Problems

    Yes, I’m still having problems
    DO NOT run the READ ME again!!!! And DO NOT move on to Step 4 below!!! "

    Am I being too literal? I've left the scan open so I can still have the program fix it the best it can.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, you are being too literal. Have SAS fix what it finds. Then run it again and attach the new log.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds