Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: My 1st bad, (?) virus: I don't even know where to start on this. I'm stuck...  (Read 15675 times)

0 Members and 1 Guest are viewing this topic.

DennisT

    Topic Starter


    Beginner
    We have 3 computers here at home.  I try really hard to maintain them.  Always updating; they always have AV.  I was really blind-sided by this last night.

    Problem is 5 yr old HP 4805 laptop, with Win. XP, SP2, etc.  We have wireless router running for household.  I use AVG AV on everything else here, but after a MS update a couple years ago I had trouble loading AVG so switched to Avast' AV for this laptop only.  Seemed to work OK.  This laptop is the, "floater," for household and various kids, (yeah, that's bad already).  So every few weeks I snag it as it goes by and check updating and AV.  Dump, for example, grand-daughter's left-in 10 layers of doll house games, etc. 

    A short time ago I got it, turned it on and Avast had expired.  Wanting to try AVG again, I went to add/delete and deleted Avast.  Marked a new restore-point as, "before  new AVG."  Downloaded AVG successfully and updated it. 

    Last night one of the older grand-kids brought it in with, "problems."  Turned it on and got all kinds of virus flags.  I tried to open AVG and got window saying AVG.exe infected and would not open.  The original HP factory loaded, "try me-pay me later," AV threw a window which I eventually tried.  That merely ran a 60 second, "scan," scrolled a ton of various virus example names and offered to sell me a fix if I bought it on line.  So much for that.

    This morning I tried to get into Help and Support to activate the old restore point but got same window, Help & Support is infected and cannot open.

    I have NO programs or archives in the laptop that are important.  No tax info, banking etc. info at all.  I could easily dump the whole thing and reload from scratch if it comes to that.  (Can't remember, though, if HP included an XP disc)

    SO:  I don't know where to begin.  I tried to do my homework here in this forum and read before posting topic.  I don't know if this is virus or malware, or both.  (What's the difference?)  I see a post to download, (if possible), highjackthis and re-naming it.  (Where-ever things are re-named).  ????

    I'd pack the whole thing to a computer store but I'm 67 and with retirement income what it is I need to try something myself.  I can get around computer operations OK, but I'm not a guru-hobbist that lives with them.  So I need specific directions.

    If someone can give me a tip where to begin that would be wonderful.  Thanks for listening, Dennis


    Allan

    • Moderator

    • Mastermind
    • Thanked: 1260
    • Experience: Guru
    • OS: Windows 10
    Please follow the instructions in the following link and post your logs:
    http://www.computerhope.com/forum/index.php/topic,46313.0.html

    DennisT

      Topic Starter


      Beginner
      Thank you, Allan:
      I had found your link when doing homework earlier.  I just was not certain if that was where I needed to begin.  I'm now using that.  I have always been told my wireless router was my firewall and to install no others.  I've stayed with that.

      I do not use TeaTime, so skipped that.

      I am now trying to access Control Panel and if successful, will list here any unusual items shown under add/delete.

      Dennis

      DennisT

        Topic Starter


        Beginner
        When I try to bring up control panel, add or remove programs, I get window that says rundll32.exe is infected and application cannot be executed.

        Where do I go next on the trouble shooting chart?

        Dennis

        DennisT

          Topic Starter


          Beginner
          The only, original factory skeleton AV in this laptop just popped up a window that included the following:

          virus:  Win32/Nugel.E
          attacked from 147.77.153.71, port 27047
          attacked port 7793

          A few minutes later same window says something about, "BankerFoxA." 

          I hope my laptop is not currenting communiting with the internet drawing in more junk/risk.  ??

          Dennis

          SuperDave

          • Malware Removal Specialist


          • Genius
          • Thanked: 1020
          • Certifications: List
          • Experience: Expert
          • OS: Windows 10
          Hello and welcome to Computer Hope Forum. My name is Dave. I will be helping you out with your particular problem on your computer. I am working under the guidance of one of the specialist of this forum so it may take a bit longer to process your logs.

          1. I will be working on your Malware issues. This may or may not solve other issues you have with your machine.
          2. The fixes are specific to your problem and should only be used for this issue on this machine.
          3. If you don't know or understand something, please don't hesitate to ask.
          4. Please DO NOT run any other tools or scans while I am helping you.
          5. It is important that you reply to this thread. Do not start a new topic.
          6. Your security programs may give warnings for some of the tools I will ask you to use. Be assured, any links I give are safe.
          7. Absence of symptoms does not mean that everything is clear.

          If you can't access the internet with your infected computer you will have to download and transfer any programs to the computer you're using now and transfer them to the infected computer with a CD-RW or a USB storage device. I prefer a CD because a storage device can get infected. If you use a storage device hold the shift key down while inserting the USB storage device for about 10 secs. You will also have to transfer the logs you receive back to the good computer using the same method until we can get the computer back on-line.
          *******************************
          Please download and run the below tool named Rkill (courtesy of BleepingComputer.com) which may help allow other programs to run.
          Save Rkill to your desktop.

          There are 4 different versions. If one of them won't run then download and try to run the other one.
           
          Vista and Win7 users need to right click Rkill and choose Run as Administrator
           

          You only need to get one of these to run, not all of them. You may get warnings from your antivirus about this tool, ignore them or shutdown your antivirus.

          Rkill.exe
          Rkill.com
          Rkill.scr
          Rkill.pif

          Once you've gotten one of them to run then try to immediately run the following.
           
          Now download and Run exeHelper.

          Please download exeHelper from Raktor to your desktop. Double-click on exeHelper.com to run the fix. A black window should pop up, press any key to close once the fix is completed. A log file named log.txt will be created in the directory where you ran exeHelper.com Attach the log.txt file to your next message.

          Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).

          ***************************************
          SUPERAntiSpyware

          If you already have SUPERAntiSpyware be sure to check for updates before scanning!


          Download SuperAntispyware Free Edition (SAS)
          * Double-click the icon on your desktop to run the installer.
          * When asked to Update the program definitions, click Yes
          * If you encounter any problems while downloading the updates, manually download and unzip them from here
          * Next click the Preferences button.

          •Under Start-Up Options uncheck Start SUPERAntiSpyware when Windows starts
          * Click the Scanning Control tab.
          * Under Scanner Options make sure only the following are checked:

          •Close browsers before scanning
          •Scan for tracking cookies
          •Terminate memory threats before quarantining
          Please leave the others unchecked

          •Click the Close button to leave the control center screen.

          * On the main screen click Scan your computer
          * On the left check the box for the drive you are scanning.
          * On the right choose Perform Complete Scan
          * Click Next to start the scan. Please be patient while it scans your computer.
          * After the scan is complete a summary box will appear. Click OK
          * Make sure everything in the white box has a check next to it, then click Next
          * It will quarantine what it found and if it asks if you want to reboot, click Yes

          •To retrieve the removal information please do the following:
          •After reboot, double-click the SUPERAntiSpyware icon on your desktop.
          •Click Preferences. Click the Statistics/Logs tab.

          •Under Scanner Logs, double-click SUPERAntiSpyware Scan Log.

          •It will open in your default text editor (preferably Notepad).
          •Save the notepad file to your desktop by clicking (in notepad) File > Save As...

          * Save the log somewhere you can easily find it. (normally the desktop)
          * Click close and close again to exit the program.
          *Copy and Paste the log in your post.
          ************************************

          Please download Malwarebytes Anti-Malware from here.

          Double Click mbam-setup.exe to install the application.
          • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes Anti-Malware, then click Finish.
          • If an update is found, it will download and install the latest version.
          • Once the program has loaded, select "Perform Full Scan", then click Scan.
          • The scan may take some time to finish,so please be patient.
          • When the scan is complete, click OK, then Show Results to view the results.
          • Make sure that everything is checked, and click Remove Selected.
          • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart. (See Extra Note)
          • Please save the log to a location you will remember.
          • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
          • Copy and paste the entire report in your next reply.
          Extra Note:

          If MBAM encounters a file that is difficult to remove,you will be presented with 1 of 2 prompts,click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.
          *****************************************
          Download Security Check by screen317 from one of the following links and save it to your desktop.

          Link 1
          Link 2

          * Unzip SecurityCheck.zip and a folder named Security Check should appear.
          * Open the Security Check folder and double-click Security Check.bat
          * Follow the on-screen instructions inside of the black box.
          * A Notepad document should open automatically called checkup.txt
          * Post the contents of that document in your next reply.

          Note: If a security program requests permission from dig.exe to access the Internet, allow it to do so.

          Windows 8 and Windows 10 dual boot with two SSD's

          DennisT

            Topic Starter


            Beginner
            Thank you, Dave:

            First, this laptop has a built in wireless adapter.  I run a wireless router here which includes serving the desktop machine I am typing this on.  Do I need to disable the wireless feature from the infected laptop before I do anything else?  (If so, how?)  (I've tried a few things and wondered if the virus would try to access the internet to cause more problems, that's why I'm asking)

            Otherwise, I'm ready to follow your instructions.  Some sound a bit complicated, but I can ask more questions along the line and I'm not in a hurry.

            Dennis

            SuperDave

            • Malware Removal Specialist


            • Genius
            • Thanked: 1020
            • Certifications: List
            • Experience: Expert
            • OS: Windows 10
            Quote
            Do I need to disable the wireless feature from the infected laptop before I do anything else?  (If so, how?)  (I've tried a few things and wondered if the virus would try to access the internet to cause more problems, that's why I'm asking)
            No. Don't disable the wireless. But if you ever need to disable it there should be a small button on your laptop to do this. Please proceed with the rest of the instructions.
            Windows 8 and Windows 10 dual boot with two SSD's

            DennisT

              Topic Starter


              Beginner
              Dave and All:
              This is curious stuff..........
              Turned laptop on today following your directions to continue.  I tried to go on line to download the Rkill program and just got screen that said couldn't access internet.  (Keep in mind we are on a radio wireless high speed here that runs from our house to next farm, -10 miles-, from there to grain elevator and into town.  Often we can't get on line)  Anyway, I could work from this desk machine so I downloaded Rkill onto a CD and then downloaded exe.Helper on second  CD.

              Shoved the Rkill disc into laptop.  Brought up a black window showing Rkill and blinking cursor.  After about 15 seconds it went blank.  I was uncertain if Rkill did anything at all.  In case it did, I put in exe-Helper disc and it brought up the window showing it's icon.  Clicked on icon and asked it to run.  Immediately I got a window that it was having trouble and did I want to report to MicroSoft.  I said no, and figured I hit a dead end.

              Then I got a window from the laptop's original skimpy AV program asking if I wanted to quarantine malware?  Knowing I was departing from your directions a bit, I clicked yes.  After that I was able to get the Grisoft AVG to open, (before it wouldn't saying it was infected).  I was able to run a scan.  Scan found two corrupted files and maleware, "Trojan.FakeAVIGen39."  It put that into the virus vault. 

              Then I rebooted.  Laptop came up showing no obvious signs anything was wrong.  I brought up AVG again and ran a second, complete scan which then showed no problems. 

              Now what do you suggest?  Sorry I departed from your suggestions but I thought I saw an, "open door," and I jumped through it.  I notice you seem to recommend, "SUPERantispyware,"  Should I download that?  I have, "Spybot, Search and Destroy," but didn't use it recently. 

              Lastly, I'm still having trouble getting on line but I'm holding off getting excited about for the moment.  And I still do not trust this machine is clean. 

              I might consider deleting Spybot and installing Superantispyware and running it.

              ?

              Dennis

              DennisT

                Topic Starter


                Beginner
                Update:
                Ran the laptop several times, rebooting between sessions.  All Grisoft AVG and Spybot scans now returning clean.  (But I don't trust even that)  However, MS Internet Explorer 7 will still not find it's way on line.  Merely returns the same largely white screen that it cannot access the internet, "maybe I'm not connected, " etc.  All other computers in the house accessing fine.  So I think the infection glitched IE.  Otherwise laptop seems to be functioning fine although I've not tried doing a lot.

                I did remember I have hundreds of condensed, low res thumbnail logging/railroad photos  in this machine in pdf groups.  I've not tried to access those.  I wonder if infections interfer with such files? 

                Tips on a more comprehensive cleaning and repair/replacement of IE would be appreciated.  I hope I did my part sufficiently well on all this....I'm really trying hard.

                Thank you,
                Dennis

                DennisT

                  Topic Starter


                  Beginner
                  More update:
                  Just fired up the laptop and updated Grisoft AVG.  Then ran scan.  Picked up," Trojan Horse Generic39.CBVD."  So something is still residing in this machine somewhere.

                  I'm wondering if I need a more powerful cleaning agent.

                  Dennis

                  BC_Programmer


                    Mastermind
                  • Typing is no substitute for thinking.
                  • Thanked: 1140
                    • Yes
                    • Yes
                    • BC-Programming.com
                  • Certifications: List
                  • Computer: Specs
                  • Experience: Beginner
                  • OS: Windows 11
                  you haven't posted any of the logs SuperDave requested.
                  I was trying to dereference Null Pointers before it was cool.

                  DennisT

                    Topic Starter


                    Beginner
                    BC:
                    That's because I've had nothing yet to post.  I had once read warnings about multiple spyware programs having conflict, that's why I asked earlier if I could continue with Superantispyware, etc., having SpyBot already.  I eventually answered my own question when I carefully read Dave's signature line showing he was running both.  My laptop no longer will access the internet, so I downloaded SuperantiSpy on this machine, put it on CD and put it in my laptop.  I doubt it could request updates but I ran it anyway.  I now have that log via Notepad.  I'm next downloading the other programs as Dave asked and will accumulate all logs to post when finished.  I'll move the logs onto a CD, load that on this machine, then I can cut/paste to forum post.

                    Dennis

                    DennisT

                      Topic Starter


                      Beginner
                      I hope this works.  Here are the logs. 

                      Back when trying to run Rkill and exe.helper I didn't get any info back;  (Not sure laptop was doing well then)

                      I'll post now and see if any of this works. 

                      Looks like, "checkup," sees me as having one poor security area.  (Like the teacher scolding the kid)

                      Dennis

                      [recovering disk space - old attachment deleted by admin]

                      DennisT

                        Topic Starter


                        Beginner
                        Well, only the final attachment made it.  Guess I'll do each separately.

                        This should the the SASpyware report.

                        Dennis

                        [recovering disk space - old attachment deleted by admin]