Windows 7 Forums


Windows 7: Viral Infection

19 Jul 2011   #1

Windows 7 Home
Maryland
 
 
Viral Infection

Hey guys.. I think my computer might be infected with a horrific virus caused by downloading a fake Flash update. I believe it's called the "Koob Virus"? It was done via Facebook..

I have Geek Squad support, but I was wondering if there might be a way for me to fix this myself. If not, I'll just take my guy in.

Thanks!

My System SpecsSystem Spec

19 Jul 2011   #2

Windows 7 64b Ultimate
Netherlands
 
 

Hello Duchess, welcome to SF!

If you're up to it.. follow these steps:

Quote:
Here is a step by step process to remove the dreaded facebook virus:
1 – Kill these processes:
fbtre6.exe
mstre6.exe
2 – Delete these registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
3 – Delete these files:
C:\\Windows\\fbtre6.exe
C:\\Windows\\fmark2.dat
Next, run a full system scan with an updated good AV
and a full scan with Malwarebytes
My System SpecsSystem Spec
19 Jul 2011   #3

Windows 7 Home
Maryland
 
 

Unfortunately, my computer keeps restarting once I log into Windows. :/ I haven't been able to do much of anything!
My System SpecsSystem Spec
.


19 Jul 2011   #4

Windows 7 64b Ultimate
Netherlands
 
 

Try booting in Safe mode: Safe Mode
My System SpecsSystem Spec
19 Jul 2011   #5

Windows 7 Ultimate x86
Massachusetts
 
 

You could try a system restore to a point before you accepted that fake update. But even if that seems to work, I would start with downloading and running this:
Malwarebytes : Malwarebytes Anti-Malware is a free download that removes viruses and malware from your computer


If everything fails, this is what I found on technocrati (if it is indeed the Koob Virus):
Quote:
1 – Kill these processes:
fbtre6.exe
mstre6.exe

2 – Delete these registry values:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating

3 – Delete these files:
C:\\Windows\\fbtre6.exe
C:\\Windows\\fmark2.dat
Make sure to ask if you don't understand something before you go about messing in the registry!
Once everything is back to working order Make a Backup:
Macrium Reflect FREE Edition - Information and download

-DG
Edit: too slow
My System SpecsSystem Spec
19 Jul 2011   #6

Windows 7 Home
Maryland
 
 

I've tried this, too. In fact, my computer automatically starts in SafeMode every time it restarts (on it's own..) but then it restarts, again!
My System SpecsSystem Spec
19 Jul 2011   #7

Win 7 Pro 64-bit
South Central Texas
 
 

You'll need access to another computer that's not infected. You can create a bootable disc from Microsoft that will scan your infected machine before it gets to the Windows 7 boot process.

http://www.sevenforums.com/tutorials...m-sweeper.html
My System SpecsSystem Spec
19 Jul 2011   #8

Windows 7 Home
Maryland
 
 

Ugh, don't have one, at the moment.. looks like I'll have to take him in.
My System SpecsSystem Spec
19 Jul 2011   #9

Win 7 Pro 64-bit
South Central Texas
 
 

Quote   Quote: Originally Posted by DuchessOfDork View Post
Ugh, don't have one, at the moment.. looks like I'll have to take him in.
Just a thought ... public library, Kinkos, neighborhood school (especially if they have any continuing education/summer school classes. )
My System SpecsSystem Spec
Reply

 Viral Infection problems?



Thread Tools



Similar help and support threads for: Viral Infection
Thread Forum
Going viral: Millions watch Microsoft Surface crash during debut Chillout Room
Need An Opinion On Anti-Viral Software System Security
Possible infection? System Security


All times are GMT -5. The time now is 05:59 AM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32