Virus Attack

Discussion in 'Malware Help (A Specialist Will Reply)' started by Kenkita, Aug 22, 2013.

  1. Kenkita

    Kenkita Private E-2

    I followed the steps as instructed in the "Read Me First" notice, but I am still having problems. Connection to the Internet is hit and miss. I now have connection to the Internet after following the directed steps, but the pages do not display. I have to refresh a few times before they appear. In Windows 7 (64 bit), when I tick the network discovery and share to "on," it doesn't take, so I cannot access my home network. Is this damage remaining from the viruses? Does a fix exist for these problems?

    Attached are the logs:

    RogueKiller
    Malwarebytes
    TDSSKILLER
    HitmanPro
    MGtools

    Your help is greatly appreciated.
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    http://img827.imageshack.us/img827/1263/frst.gif For 32-bit (x86) systems download Farbar Recovery Scan Tool and save it to a flash drive.
    For 64-bit (x64) systems download Farbar Recovery Scan Tool x64 and save it to a flash drive.

    Plug the flashdrive into the infected PC.

    Enter System Recovery Options.

    To enter System Recovery Options from the Advanced Boot Options:
    • Restart the computer.
    • As soon as the BIOS is loaded begin tapping the F8 key until Advanced Boot Options appears.
    • Use the arrow keys to select the Repair your computer menu item.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account and click Next.

    To enter System Recovery Options by using Windows installation disc:

    • Insert the installation disc.
    • Restart your computer.
    • If prompted, press any key to start Windows from the installation disc. If your computer is not configured to start from a CD or DVD, check your BIOS settings.
    • Click Repair your computer.
    • Choose your language settings, and then click Next.
    • Select the operating system you want to repair, and then click Next.
    • Select your user account an click Next.
    On the System Recovery Options menu you will get the following options:
    • Select Command Prompt
    • In the command window type in notepad and press Enter.
    • The notepad opens. Under File menu select Open.
    • Select "Computer" and find your flash drive letter and close the notepad.
    • In the command window type e:\frst.exe (for x64 bit version type e:\frst64) and press Enter
    • Note: Replace letter e with the drive letter of your flash drive.
    • The tool will start to run.
    • When the tool opens click Yes to disclaimer.
    • Press Scan button.
    • It will make a log (FRST.txt) on the flash drive. Please attach this log to your next reply. (How to attach)
     
  3. Kenkita

    Kenkita Private E-2

    Thank you so much for your response. I've been beside myself with these viruses.

    It appears that the "Read Me First" steps worked--Fingers crossed--, although I'm still having Internet connection issues. I'm not sure whether this is virus related.

    I was able to establish a network connection by importing the SharedAccess key from my other computer in the home network.

    I don't have the Windows 7 installation disk to complete the next set of steps you have sent me. However, I did download the FANBAR Recovery Scan Tool x64 and completed the scan. It also generated an "addition" log, which I have attached along with the FRST log.

    Do the logs look copacetic?

    Thank you so much for your assistance.
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    NOTICE: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system

    Attached is fixlist.txt
    • Save fixlist.txt to your flash drive.
    • You should now have both fixlist.txt and FRST64.exe on your flash drive.

    Now re-enter System Recovery Options.
    Run FRST64 and press the Fix button just once and wait.
    The tool will make a log on the flashdrive (Fixlog.txt).
    Please attach this to your next message. (How to attach)


    Now see if you are able to continue on with the malware removal instructions. :)

    READ & RUN ME FIRST. Malware Removal Guide
     

    Attached Files:

  5. Kenkita

    Kenkita Private E-2

    Thank you for the fixlist. I ran it, and I have attached the log and the scan completed after applying the fix.

    I noticed that the fixlog shows the following as needing completion outside recovery mode:

    Error: The HKCU key should be fixed outside recovery mode.
    Error: The HKCU key should be fixed outside recovery mode.
    SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = http://search.ask.com/web?q={searchterms}&l=dis&o=HPDTDF => Error: The entry should be fixed outside recovery mode.

    However, I noticed in the scan report that they no longer appear.

    Before I proceed with the completion of the malware removal as instructed, are the following files/keys questionable and is it safe to have the FANBAR tool remove these?:

    HKU\Angelica Duran\...\Run: [AdobeBridge] - [x]
    HKLM-x32\...\Run: [] - [x]
    HKU\Guest.KENKA\...\Run: [LightScribe Control Panel] - C:\Program Files (x86)\Common Files\LightScribe\LightScribeControlPanel.exe -hidden [x]

    I noticed that they have an "[x]" after the file names. I removed LightScribe from my computer many months ago (if not an year ago). I don't know what the other two are.

    I'll continue to monitor my computer for any unusual behavior.

    Your help is much appreciated through this arduous process :)
     

    Attached Files:

  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can remove them. :) Adobe is legit but you do not need it to run on start up.
     
  7. Kenkita

    Kenkita Private E-2

    Hi once again :)

    I followed the last steps as directed by completing Step 5 successfully, but Step 6 (Toggle System Restore) doesn't appear to work. The system restore points (8/23/2013; 8/21/2013; 1/20/2013) are still showing up. Is there any way to successfully delete them and create a new system restore point with the clean system?

    Thank you for all your help. The computer is running smoothly at this point, and I wouldn't have been able to remove the infection without your help. I'm now hoping to create a clean system restore point.
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    How far did you get with it? Did you actually disable and then reenable it?
     
  9. Kenkita

    Kenkita Private E-2

    Yes, I disabled it; then I restarted the computer, but when I checked they kept showing up. I just now created a restore point, and when I checked, the other three are not longer showing up. It looks like they were successfully deleted.

    I set Internet Explorer 10 to "enable enhanced protection mode" because when I turned on the UAC on to "always notify" IE wouldn't start up, unless I used "run as administrator."

    The only problem is that Adobe PDF doesn't work with "enable enhanced protection mode." Do you know of a fix?

    Thank you :) Everything is just about done.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    I'm afraid you'd have to ask in the software forum about that. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds