Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Virus?  (Read 17511 times)

0 Members and 1 Guest are viewing this topic.

UnstableWingman

    Topic Starter


    Rookie

    Re: Virus?
    « Reply #30 on: February 15, 2009, 11:03:08 PM »
    I think this is it..?

    Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net

    device: opened successfully
    user: MBR read successfully
    kernel: MBR read successfully
    user & kernel MBR OK

    tgp1994



      Beginner

    • Think happy thoughts and have a nice day.
    • Thanked: 2
      • Yes
    • Experience: Experienced
    • OS: Other
    Re: Virus?
    « Reply #31 on: February 15, 2009, 11:05:35 PM »
    Ok, reboot your computer without the CD and see if it works.

    evilfantasy

    • Malware Removal Specialist
    • Moderator


    • Genius
    • Calm like a bomb
    • Thanked: 493
    • Experience: Experienced
    • OS: Windows 11
    Re: Virus?
    « Reply #32 on: February 15, 2009, 11:07:58 PM »
    tgp1994 , please. I have this under control and we need to do things in a certain order.

    Now since we found that hiding we need to run more scans.

    Run CCleaner and then restart the computer (hopefully without the disk)

    The F-Secure scan can take a while so you might want to be sure you have enough time, over an hour...

    You can go and delete the MBR.exe and all of the log files it created.

    Run the F-Secure Online Scanner for Viruses, Spyware and RootKits.

    Note: This Scanner is for Internet Explorer Only!
    • Click on Online Services and then Online Scanner
    • Accept the License Agreement.
    • Once the ActiveX installs,Click Full System Scan
    • Once the download completes,the scan will begin automatically.
    • The scan will take some time to finish,so please be patient.
    • When the scan completes, click the Automatic cleaning (recommended) button.
    • Click the Show Report button and Copy&Paste the entire report in your next reply.
    .
    ----------

    Now run GMER and post the log along with the F-Fecure log.

    Please read this carefully.

    Download GMER and save it to your desktop
    • Unzip (extract) it to your desktop.
    • Disconnect from Internet and close all running programs.
    • There is a small chance this application may crash your computer so save any work you have open.
    • Double-click gmer.exe to run it.
    • Let the gmer.sys driver to load if asked.
    • If it gives you a warning at program start about rootkit activity and asks if you want to run a scan... click NO
    • Click the Rootkit tab.
    • Make sure all the boxes on the right of the screen are checked, EXCEPT for "Show All".
    • Then click the Scan button. Wait for the scan to finish.
    • Once done, click the Copy button.
    • This will copy the results to the clipboard. Open Notepad and press CTRL + V to paste the log, and save it to your desktop.
    • Add this log to your next reply.
    NOTE: If you're having problems with running gmer.exe, try it in Safe Mode. This tool works in Safe Mode whereas many other rootkit revealers do not.


    UnstableWingman

      Topic Starter


      Rookie

      Re: Virus?
      « Reply #33 on: February 15, 2009, 11:14:50 PM »
      Okay.
      Reboot worked without the CD.
      I have run Firefox for the past year, so what program would you suggest instead of F-Secure?

      evilfantasy

      • Malware Removal Specialist
      • Moderator


      • Genius
      • Calm like a bomb
      • Thanked: 493
      • Experience: Experienced
      • OS: Windows 11
      Re: Virus?
      « Reply #34 on: February 15, 2009, 11:16:37 PM »
      Nothing. IE is the only way.

      You still have to use IE to go to Windows Updates so it can't be completely abandoned.

      UnstableWingman

        Topic Starter


        Rookie

        Re: Virus?
        « Reply #35 on: February 15, 2009, 11:21:16 PM »
        Can I run GMER and F-Secure at the same tiime?

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Virus?
        « Reply #36 on: February 15, 2009, 11:22:59 PM »
        No, never a good idea. GMER won't take very long. It's the full version of the MBR.exe you ran.

        evilfantasy

        • Malware Removal Specialist
        • Moderator


        • Genius
        • Calm like a bomb
        • Thanked: 493
        • Experience: Experienced
        • OS: Windows 11
        Re: Virus?
        « Reply #37 on: February 15, 2009, 11:23:49 PM »
        But I need F-secure to find/remove anything it encounters before GMER is run.

        UnstableWingman

          Topic Starter


          Rookie

          Re: Virus?
          « Reply #38 on: February 16, 2009, 12:05:06 AM »
          Kay, done.

          [attachment deleted by admin]

          evilfantasy

          • Malware Removal Specialist
          • Moderator


          • Genius
          • Calm like a bomb
          • Thanked: 493
          • Experience: Experienced
          • OS: Windows 11
          Re: Virus?
          « Reply #39 on: February 16, 2009, 12:16:08 AM »
          Clean!! The computer is running OK now right?

          Time to clean up the mess.

          • Click START then RUN
          • Now type Combofix /u in the runbox
          • Make sure there's a space between Combofix and /u
          • Then hit Enter.
          .
          .
          The above procedure will:
          • Delete:
            • ComboFix and its associated files and folders.
            • VundoFix backups, if present
            • The C:\Deckard folder, if present
            • The C:_OtMoveIt folder, if present
            • Reset the clock settings.
            • Hide file extensions, if required.
            • Hide System/Hidden files, if required.
            • Set a new, clean Restore Point.
            .
            ----------

            Use the Secunia Software Inspector to check for out of date software.
            • Click Start Now
            • Check the box next to Enable thorough system inspection.
            • Click Start
            • Allow the scan to finish and scroll down to see if any updates are needed.
            • Update anything listed.
            .
            ----------

            Go to Microsoft Windows Update and get all critical updates.

            ----------

            Here are some great FREE tools to help you keep from getting infected again. These tools use little or no resources so won't slow down your PC.

            To prevent unknown applications from being installed on your computer install WinPatrol 2008
            * Using Winpatrol to protect your computer from malicious software

            I suggest using WOT - Web of Trust. WOT is a free Internet security addon for your browser. It will keep you safe from online scams, identity theft, spyware, spam, viruses and unreliable shopping sites. WOT warns you before you interact with a risky website. It's easy and it's free.

            SpywareBlaster - Secure your Internet Explorer to make it harder for ActiveX programs to run on your computer. Also stop certain cookies from being added to your computer when running Mozilla based browsers like Firefox.
            * Using SpywareBlaster to protect your computer from Spyware and Malware
            * If you don't know what ActiveX controls are, see here

            Check out Keeping Yourself Safe On The Web for tips and free tools to help keep you safe in the future.

            Also see Slow Computer? It May Not Be Malware for free cleaning/maintenance tools to help keep your computer running smooth.

            UnstableWingman

              Topic Starter


              Rookie

              Re: Virus?
              « Reply #40 on: February 16, 2009, 12:33:18 AM »
               ;D

              Thank you so much! My parents kept bugging me to take it in, and I didnt want to go through all the trouble. If anyone I know has any problems, ill make sure to direct them here.

              Thanks again!!

              evilfantasy

              • Malware Removal Specialist
              • Moderator


              • Genius
              • Calm like a bomb
              • Thanked: 493
              • Experience: Experienced
              • OS: Windows 11
              Re: Virus?
              « Reply #41 on: February 16, 2009, 12:36:50 AM »
              Your welcome, and thanks to BC_Programmer also for mentioning the MBR.

              Safe surfing...

              tgp1994



                Beginner

              • Think happy thoughts and have a nice day.
              • Thanked: 2
                • Yes
              • Experience: Experienced
              • OS: Other
              Re: Virus?
              « Reply #42 on: February 16, 2009, 08:11:52 AM »
              Lol I seem to remember someone on this topic telling me CCleaner is worthless in this situation... And then restart your computer? I feel plagiarized  :-X

              BC_Programmer


                Mastermind
              • Typing is no substitute for thinking.
              • Thanked: 1140
                • Yes
                • Yes
                • BC-Programming.com
              • Certifications: List
              • Computer: Specs
              • Experience: Beginner
              • OS: Windows 11
              Re: Virus?
              « Reply #43 on: February 16, 2009, 09:31:29 AM »
              Lol I seem to remember someone on this topic telling me CCleaner is worthless in this situation

              It was worthless since he had a MBR rootkit.

              CCleaner was suggested after the computer was declared clean from malware as a set of final steps- it of course does not in and of itself clean any malware infections, especially not MBR viruses.

              In any case, regardless of the quality of advice offered by non-malware specialists, people seeking help are advised that they follow such advice at their own risk- And, generally, such advice should only be given before a malware expert has responded to the thread (An ideal example of which is to point the person seeking help to the malware removal guide, which also helps the malware expert that comes along as they won't need to do the same thing, and it gives the person something to do as they wait for said expert), responses made after a malware expert has "taken the case" so to speak is generally considered rude regardless of the quality of such advice.

              If you really want to provide malware removal assistance, though:

              http://www.computerhope.com/forum/index.php/topic,57605.0.html


              Also, don't take it personally, as I said, it's not a declaration that your advice isn't sound- it's merely to protect the visitor from various cases where a non-experts advice can make the problem worse- the visitor has no way to judge good or bad information- if they could do that they could likely solve the issue on their own - so the suggestions given to the visitor in the "read before..." thread is to take all posts from non-malware experts with a grain of salt.

              personally, I kind of consider the "computer viruses and spyware" forum more or less the territory of the malware experts. Being that they are shortstaffed (as usual  ::)) it does help to make sure posters run through the malware guide and post their logs, since that is almost always the first step required in order to gain information about the "victim" machine, but other then that (and stuff I'm 100% certain is causing the issue) I myself refrain from posting as I have learned through several posts that I can't read logs from computers other then my own very well at all- since unlike with my own PC I haven't a clue what hardware and software environment the log was generated under.


              Another point of note is seemingly useless "informational" posts. To draw another analogy from myself, I once posted a large rant about Javascript not being Java and blah blah blah- this post wasn't addressed at all but I thought about it shortly afterward and realized that I was being more annoying then informational. the experts, after all, know what they are doing and have a very high success rate at removing malware, and my little speel likely did nothing but confuse the poor soul trying to receive help.


              EDIT:

              why do I always start posting before somebody else, but then somebody else posts something else that essentially sums up what I say...  lol
              I was trying to dereference Null Pointers before it was cool.

              kpac

              • Web moderator


              • Hacker

              • kpac®
              • Thanked: 184
                • Yes
                • Yes
                • Yes
              • Certifications: List
              • Computer: Specs
              • Experience: Expert
              • OS: Windows 7
              Re: Virus?
              « Reply #44 on: February 16, 2009, 09:37:36 AM »
              Lol I seem to remember someone on this topic telling me CCleaner is worthless in this situation... And then restart your computer? I feel plagiarized  :-X

              CCleaner doesn't clean malware does it? ::)