| Windows 7: Virus Help Needed |
31 Mar 2011
|
| | Windows 7 Ultimate SP1 x64 850 posts Southern California |
Virus Help Needed Just today I got an Virus on one of my home computers. It disabled MSE and disallows me from accessing any resources, running programs, or starting the task manager or system tools like cmd.
I can still access Safe Boot mode and ran MSE from safe boot, but the virus/ rouge AV is still on the computer, other than that It turns the desktop a blue color and floods my router with high pings, I can see this from router logs.
Here are some pics, I had to take them with my cell because it disabled the Snipping Tool. 
Any help on removing this rouge AV would be much appreciated! | My System Specs |
| System Manufacturer/Model Number HP Pavilion g7-1350dx OS Windows 7 Ultimate SP1 x64 CPU AMD A6-3420M APU Memory 4.0 Gb DDR3 838 MHz Graphics Card AMD Radeon HD 6520G Sound Card IDT HD Audio Screen Resolution 1900x 600 Hard Drives 500GB Hitachi HTS547550A9E384 |
31 Mar 2011
|
| | Windows 7 x64 6,737 posts Houston |
boot in safe mode with networking Safe Mode
If that keeps it from launching at that point you can download install and allow to update malwarebytes antimalware Malwarebytes (free version)
Run a full scan and let it do it's thing and clean it out.
That should return you to a position where you can boot normally.
If you can't launch any applications the attached file should return that to normal (all this still needs to be done in safe mode.) | My System Specs | | System Manufacturer/Model Number Insane hobo technologies. ;-) OS Windows 7 x64 CPU Intel i7 2600k Motherboard Asrock z68 extreme 4 gen 3 Memory G.skill Ripjaw 16gigs @ 1866 Graphics Card Nvidia gtx580 (evga) Sound Card Integrated HD audio + hdmi Monitor(s) Displays 24" ASUS widescreen + 42" insignia Screen Resolution 1080p (1920x1080) Keyboard Microsoft wireless 3000 (v2) Mouse MS - wireless 5000 (bluetrack) PSU 1 kilowatt SLI/Crossfire rated Silverstone modular Case NZXT Phantom + additional 220 fan Cooling Zalmann Hard Drives 128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA) Internet Speed depends on if you ask me or my provider. Other Info The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism. |
31 Mar 2011
|
| | Windows 7 Ultimate SP1 x64 850 posts Southern California |
I am able to boot into safe mode and am running a full scan with malwarebytes right now, I will post the log files as soon as it finishes. | My System Specs | | System Manufacturer/Model Number HP Pavilion g7-1350dx OS Windows 7 Ultimate SP1 x64 CPU AMD A6-3420M APU Memory 4.0 Gb DDR3 838 MHz Graphics Card AMD Radeon HD 6520G Sound Card IDT HD Audio Screen Resolution 1900x 600 Hard Drives 500GB Hitachi HTS547550A9E384 |
31 Mar 2011
|
| | Windows 7 x64 6,737 posts Houston |
when it's done it will give you the option to clean up the mess it finds on the ...bottom right I believe, it's been so long since I was actually infected with anything I'm not sure I'm remembering that little detail right.
It does a great clean up job though.
It should get rid of the problem.
Worst case scenario is afterwards you'll need to use startup repair to get it booting right again. Startup Repair
We don't want to use system restore right now though, as the restore files may actually contain the virus. Depending on how sneaky it was. | My System Specs | | System Manufacturer/Model Number Insane hobo technologies. ;-) OS Windows 7 x64 CPU Intel i7 2600k Motherboard Asrock z68 extreme 4 gen 3 Memory G.skill Ripjaw 16gigs @ 1866 Graphics Card Nvidia gtx580 (evga) Sound Card Integrated HD audio + hdmi Monitor(s) Displays 24" ASUS widescreen + 42" insignia Screen Resolution 1080p (1920x1080) Keyboard Microsoft wireless 3000 (v2) Mouse MS - wireless 5000 (bluetrack) PSU 1 kilowatt SLI/Crossfire rated Silverstone modular Case NZXT Phantom + additional 220 fan Cooling Zalmann Hard Drives 128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA) Internet Speed depends on if you ask me or my provider. Other Info The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism. |
31 Mar 2011
|
| | Windows 7 Ultimate SP1 x64 850 posts Southern California |

Quote: Originally Posted by Maguscreed when it's done it will give you the option to clean up the mess it finds on the ...bottom right I believe, it's been so long since I was actually infected with anything I'm not sure I'm remembering that little detail right.
It does a great clean up job though.
It should get rid of the problem.
Worst case scenario is afterwards you'll need to use startup repair to get it booting right again. Startup Repair
We don't want to use system restore right now though, as the restore files may actually contain the virus. Depending on how sneaky it was. OK, Its been running the scan for about 35 minutes now, I have used MalwareBytes before and I know what you mean about having to go back and deleting the files because it Quarantines them. | My System Specs | | System Manufacturer/Model Number HP Pavilion g7-1350dx OS Windows 7 Ultimate SP1 x64 CPU AMD A6-3420M APU Memory 4.0 Gb DDR3 838 MHz Graphics Card AMD Radeon HD 6520G Sound Card IDT HD Audio Screen Resolution 1900x 600 Hard Drives 500GB Hitachi HTS547550A9E384 |
31 Mar 2011
|
| | Windows 7 Ultimate SP1 x64 850 posts Southern California |
I successfully managed to remove the infected files, I have included the log files, I ran a quick scan first and then a full scan. mbam-log-2011-03-31 (20-00-54).txt Code: Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 5363
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/31/2011 8:00:54 PM
mbam-log-2011-03-31 (20-00-54).txt
Scan type: Quick scan
Objects scanned: 154371
Time elapsed: 3 minute(s), 6 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\fCd16633iHkPb16633 (Trojan.Agent.Gen) -> Value: fCd16633iHkPb16633 -> Quarantined and deleted successfully.
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\programdata\fcd16633ihkpb16633\fcd16633ihkpb16633.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\local settings\temporary internet files\Content.IE5\ZWQ3XI6W\download[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. mbam-log-2011-03-31 (20-47-25).txt Code: Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org
Database version: 6231
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
3/31/2011 8:47:25 PM
mbam-log-2011-03-31 (20-47-25).txt
Scan type: Full scan (C:\|)
Objects scanned: 269605
Time elapsed: 41 minute(s), 23 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
(No malicious items detected)
Folders Infected:
(No malicious items detected)
Files Infected:
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\60IKWZ5T\antispy2011setup[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\N6JD1KBM\antispy2011setup[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\N6JD1KBM\antispy2011setup[2].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully. | My System Specs | | System Manufacturer/Model Number HP Pavilion g7-1350dx OS Windows 7 Ultimate SP1 x64 CPU AMD A6-3420M APU Memory 4.0 Gb DDR3 838 MHz Graphics Card AMD Radeon HD 6520G Sound Card IDT HD Audio Screen Resolution 1900x 600 Hard Drives 500GB Hitachi HTS547550A9E384 |
01 Apr 2011
|
| | Windows 7 Home Premium 32 bit 5,681 posts In a house with a cat trying to kill me |
Here are a couple of other options in case Malwarebytes doesn't get it out of the system. Even if MB does remove it, it would be a good idea to run your AV or these tools and do a full system scan while disconnected from the net. Once you get a virus, it's hard to tell how much of it is left behind. And unfortunately, even one tiny file can cause it to come back and reinstall.
Microsoft Windows Malicious Software Removal Tool Download details: Microsoft® Windows® Malicious Software Removal Tool (KB890830) x64
Norton Power Eraser http://security.symantec.com/nbrt/np...origin=default | My System Specs | | System Manufacturer/Model Number Dell Hell oh Well OS Windows 7 Home Premium 32 bit CPU Intel Core 2 Duo 2.93GHz Memory Not much with my ADHD Graphics Card ATI Radeon HD 4350 Monitor(s) Displays I have one...It's bright. A 19 inch CRT actually. Keyboard It's 10 years old and amazingly still works Mouse Same deal with the mouse, 10 yrs old, if it ain't broke... Case Don't get on my case...man :D Cooling I have an Air Conditioner & Diet Pepsi Hard Drives 250 GB Main Drive, 2 - 1 TB Externals, various FD's. |
01 Apr 2011
|
| | Windows 7 Ultimate SP1 (x64) 9,922 posts South Australia |
Hi ionbasa,
Looks like Malwarebytes did the trick - its very good software.
As an additional check, can I suggest performing an online scan using the ESET on-line scanner? This just helps to give some comfort that nothing has slipped through the cracks.
Regards,
Golden | My System Specs | | Computer type PC/Desktop System Manufacturer/Model Number Golden Mk. I.3 OS Windows 7 Ultimate SP1 (x64) CPU Intel i7 860 @ 2.80 GHz Motherboard Gigabyte P55A-UD3R Rev.1. Award BIOS F13 Memory 16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24) Graphics Card EVGA NVidia GTX 560 1024MB Sound Card Realtek Integrated Monitor(s) Displays Dual Samsung SyncMaster 2494HS Screen Resolution 1920*1080 and 1920*1080 Keyboard Logitech G110 Mouse Logitech MX518 PSU Thermaltake ToughPower QFan 750W Case Thermaltake Element S VK60001W2Z Cooling Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans Hard Drives 1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
3*Samsung F1 SpinPoint 1TB in RAID5;
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0 Internet Speed Not fast enough!!! Antivirus MSE and Malwarebytes Pro Browser Chrome Version 27 Other Info Laptop: ASUS X54C, Intel Core i3-2330M @ 2.0Ghz, 4GB RAM, Intel HD on-board graphics, Windows 7 Professional SP1 (x64), LinuxMint 14 (x64), PepperMint 3 (x86) |
01 Apr 2011
|
| | Windows7 Pro 64bit SP-1; Windows XP Pro 32bit 6,487 posts Grafton,IL |
| My System Specs | | System Manufacturer/Model Number Hopalong/ Godzilla OS Windows7 Pro 64bit SP-1; Windows XP Pro 32bit CPU Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core Motherboard ASUS P7P55D-E PRO Memory 8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB Graphics Card ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5 Sound Card VIA Onboard Monitor(s) Displays Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws Screen Resolution 1920x1080; 1440x900 Keyboard Logitech K-320 Mouse Kensington PSU COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular Case COOLER MASTER HAF 932 RC-932-KKN5-GP Black Cooling Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans) Hard Drives Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s Antivirus Avast Inernet Suite Browser IE 9 ; Chrome |
01 Apr 2011
|
| | Windows 7 Ultimate SP1 x64 850 posts Southern California |
okay, Thank you for all the help, MB fixed it and than ran eset and all was clean. | My System Specs | | System Manufacturer/Model Number HP Pavilion g7-1350dx OS Windows 7 Ultimate SP1 x64 CPU AMD A6-3420M APU Memory 4.0 Gb DDR3 838 MHz Graphics Card AMD Radeon HD 6520G Sound Card IDT HD Audio Screen Resolution 1900x 600 Hard Drives 500GB Hitachi HTS547550A9E384 Virus Help Needed problems? All times are GMT -5. The time now is 05:50 PM. | |