Virus

Discussion in 'Malware Help (A Specialist Will Reply)' started by Bishar, Sep 13, 2010.

  1. Bishar

    Bishar Private E-2

    My computer is infected with a virus. When I log on to the internet it directs me to a page other than my home page. It says threat from win32/Nuqel.E

    Please help
     
  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.

    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.


    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:


    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:

    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this aother user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:

    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  3. Bishar

    Bishar Private E-2

    Tim,

    I cannot get to any site it automatically gets me to the site where it asks me to run their antivirus software.

    Bishar
     
  4. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Either try doing it in safe mode or use a different computer to download the scanning tools and transfer them via usb thumb drive or a cd.
     
  5. Bishar

    Bishar Private E-2

    I rebooted my PC (I am on windows XP) in safe mode but now it will not allow me to logon.
     
  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Try creating this disc and boot to it. ( You will need to change your bios so it boots to the cd-rom first ):
    Kaspersky Rescue Disk.
     
  7. Bishar

    Bishar Private E-2

    Tim,

    Can I go back to the normal mode.

    Bishar

    I am so screwed
     
  8. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, if you can. If normal mode is viable, then you can still either create that disc ( using a different computer ) or if you have downloaded MBAM, SAS, ComboFix and MGTools to a cd/ thumb drive, you can try installing them on the infected computer.
     
  9. Bishar

    Bishar Private E-2

    But now that I am in safe mode everytime I restart the infected computer it goes back to the safe mode even when I click f8 and the normal setup is highlighted.
     
  10. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    And you can't log into safe mode? Do you have your install cd?

    If you do, you could try doing this:
    Here is the link to the MS article How to recover from a corrupt registry.

    Otherwise, you should try the Kaspersky disc. :(
     
  11. Bishar

    Bishar Private E-2

    I have created the rescue disk. What steps do I need to take to reboot using the rescue disk. You mentioned you mentioned changing the Bios setting?
     
  12. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Yes, just like doing a clean install, you need to boot into the bios and change the boot order to cd-rom first device. I am not sure which key your system wants to get into the bios, it could be f12. Not sure. It will flash briefly when you first boot up before the OS starts to load.
     
  13. Bishar

    Bishar Private E-2

    I loaded the rescue disk but it is not booting from the disk even though my BIOS has boot from cd as the first choice.:(:(:(
     
  14. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  15. Bishar

    Bishar Private E-2

    A little headway, I got it to boot from the cd. to the page where it has the options
    Kaspery....graphic
    text
    HArware info
    boot from hard disk

    What option should i got to.
     
  16. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    There should be an option to scan your hard drive. :confused
     
  17. Bishar

    Bishar Private E-2

    Nope

    these are the options

    Kaspery Rescue disk graphic mode
    Kaspery Rescue disk text mode
    HArware info
    boot from hard disk
    reboot
    shut down
     
  18. Bishar

    Bishar Private E-2

    Tim,

    I managed to boot my computer with the Kaspersky Recovery disk. I scnned my entire computer and it said nothing harmful was detected. But when I restarted my computer from the hard drive it does not run in normal mode. The bproblem I am having is that in safe mode it will not allow me to log on to the network. How can I get my ncomputer to run in normal mode.

    Thank you.

    Bishar
     
  19. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Do you have your OS cd? You may want to try doing a repair install. This may not be a malware issue.

    You could use the UBCD4Win disc to boot into so that you can get your files and data off to a backup source. That way if you absolutely have to, you can do a clean install.
     
  20. Bishar

    Bishar Private E-2

    I found a disk called drivers and utiities. We hav three computers in this office. I am not sure it is the one to my computer. Do you think it is safe to try? Also, contents are device drivers, diagnostics and utilities and online documentation.

    If I have to do a clean install how do I go about doing that.
     
  21. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    That is just the drivers disc. You would need the original OS cd. Surely someone knows where you have those stored for your office computers.
     
  22. Bishar

    Bishar Private E-2

    TimW,

    Found an OS disk. It is still in its unopened packet. Do you think its safe to try that.
     
  23. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    As long as it is the OS for your computer, then yes. I am guessing that maybe all the computers in your office are the same and this is an OEM disc. Do you know how to do a repair install?
     
  24. Bishar

    Bishar Private E-2

    Tim

    You are dealing with a novice here. I downloaded the UBCDWin program you had talked about earlier and now I cannot burn it to a cd. That's how bad I am. So to answer your question, No I do not know how to do a repair install.

    CDan you please guide me.

    Also thank you for all your help.
     
  25. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Boot to the OS cd. Hit enter when is prompts you to hit any key to boot to the cd. You will be asked if you want to do a repair (R) or an install. Do install. It will then find your previous install and ask if you want to repair. This time do choose R. Then it will just start loading all the files.
     
  26. Bishar

    Bishar Private E-2

    TimW

    Thank you for all your help. I managed to get back into normal mode. I will run all the malware procedures and attach the files so you'll can check if there is any malware on my computer.

    Again, thank you.
     
  27. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Good to know. Do run the scans and attach the logs when you are ready.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds