Viral Infection


  1. Posts : 9
    Windows 7 Home
       #1

    Viral Infection


    Hey guys.. I think my computer might be infected with a horrific virus caused by downloading a fake Flash update. I believe it's called the "Koob Virus"? It was done via Facebook..

    I have Geek Squad support, but I was wondering if there might be a way for me to fix this myself. If not, I'll just take my guy in.

    Thanks!
      My Computer


  2. Posts : 1,808
    Windows 7 64b Ultimate
       #2

    Hello Duchess, welcome to SF!

    If you're up to it.. follow these steps:

    Here is a step by step process to remove the dreaded facebook virus:
    1 – Kill these processes:
    fbtre6.exe
    mstre6.exe
    2 – Delete these registry values:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
    HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating
    3 – Delete these files:
    C:\\Windows\\fbtre6.exe
    C:\\Windows\\fmark2.dat
    Next, run a full system scan with an updated good AV
    and a full scan with Malwarebytes
      My Computer


  3. Posts : 9
    Windows 7 Home
    Thread Starter
       #3

    Unfortunately, my computer keeps restarting once I log into Windows. :/ I haven't been able to do much of anything!
      My Computer


  4. Posts : 1,808
    Windows 7 64b Ultimate
       #4

    Try booting in Safe mode: Safe Mode
      My Computer


  5. Posts : 2,009
    Windows 7 Ultimate x86
       #5

    You could try a system restore to a point before you accepted that fake update. But even if that seems to work, I would start with downloading and running this:
    Malwarebytes : Malwarebytes Anti-Malware is a free download that removes viruses and malware from your computer


    If everything fails, this is what I found on technocrati (if it is indeed the Koob Virus):
    1 – Kill these processes:
    fbtre6.exe
    mstre6.exe

    2 – Delete these registry values:
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “c:\windows\mstre6.exe”
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”systray” = “C:\Windows\fbtre6.exe”
    HKEY_CURRENT_USER\AppEvents\Schemes\Apps\Explorer\Navigating

    3 – Delete these files:
    C:\\Windows\\fbtre6.exe
    C:\\Windows\\fmark2.dat
    Make sure to ask if you don't understand something before you go about messing in the registry!
    Once everything is back to working order Make a Backup:
    Macrium Reflect FREE Edition - Information and download

    -DG
    Edit: too slow :)
      My Computer


  6. Posts : 9
    Windows 7 Home
    Thread Starter
       #6

    I've tried this, too. In fact, my computer automatically starts in SafeMode every time it restarts (on it's own..) but then it restarts, again!
      My Computer


  7. Posts : 10,994
    Win 7 Pro 64-bit
       #7

    You'll need access to another computer that's not infected. You can create a bootable disc from Microsoft that will scan your infected machine before it gets to the Windows 7 boot process.

    https://www.sevenforums.com/tutorials...m-sweeper.html
      My Computer


  8. Posts : 9
    Windows 7 Home
    Thread Starter
       #8

    Ugh, don't have one, at the moment.. looks like I'll have to take him in.
      My Computer


  9. Posts : 10,994
    Win 7 Pro 64-bit
       #9

    DuchessOfDork said:
    Ugh, don't have one, at the moment.. looks like I'll have to take him in.
    Just a thought ... public library, Kinkos, neighborhood school (especially if they have any continuing education/summer school classes. :))
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 07:06.
Find Us