Solved Virus Help Needed

ionbasa

New member
Guru
VIP
Local time
3:22 PM
Messages
744
Just today I got an Virus on one of my home computers. It disabled MSE and disallows me from accessing any resources, running programs, or starting the task manager or system tools like cmd.

I can still access Safe Boot mode and ran MSE from safe boot, but the virus/ rouge AV is still on the computer, other than that It turns the desktop a blue color and floods my router with high pings, I can see this from router logs.

Here are some pics, I had to take them with my cell because it disabled the Snipping Tool.
IMAG0049.jpg
IMAG0050.jpg
IMAG0051.jpg
IMAG0052.jpg
Any help on removing this rouge AV would be much appreciated!
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Pavilion g7-1350dx
OS
Windows 7 Ultimate SP1 x64
CPU
AMD A6-3420M APU
Memory
4.0 Gb DDR3 838 MHz
Graphics Card(s)
AMD Radeon HD 6520G
Sound Card
IDT HD Audio
Screen Resolution
1600x 900
Hard Drives
500GB Hitachi HTS547550A9E384
boot in safe mode with networking
http://www.sevenforums.com/tutorials/69585-safe-mode.html

If that keeps it from launching at that point you can download install and allow to update malwarebytes antimalware
Malwarebytes (free version)

Run a full scan and let it do it's thing and clean it out.
That should return you to a position where you can boot normally.

If you can't launch any applications the attached file should return that to normal (all this still needs to be done in safe mode.)
 

Attachments

My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
I am able to boot into safe mode and am running a full scan with malwarebytes right now, I will post the log files as soon as it finishes.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Pavilion g7-1350dx
OS
Windows 7 Ultimate SP1 x64
CPU
AMD A6-3420M APU
Memory
4.0 Gb DDR3 838 MHz
Graphics Card(s)
AMD Radeon HD 6520G
Sound Card
IDT HD Audio
Screen Resolution
1600x 900
Hard Drives
500GB Hitachi HTS547550A9E384
when it's done it will give you the option to clean up the mess it finds on the ...bottom right I believe, it's been so long since I was actually infected with anything I'm not sure I'm remembering that little detail right.

It does a great clean up job though.
It should get rid of the problem.
Worst case scenario is afterwards you'll need to use startup repair to get it booting right again.
http://www.sevenforums.com/tutorials/681-startup-repair.html

We don't want to use system restore right now though, as the restore files may actually contain the virus. Depending on how sneaky it was.
 

My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
when it's done it will give you the option to clean up the mess it finds on the ...bottom right I believe, it's been so long since I was actually infected with anything I'm not sure I'm remembering that little detail right.

It does a great clean up job though.
It should get rid of the problem.
Worst case scenario is afterwards you'll need to use startup repair to get it booting right again.
http://www.sevenforums.com/tutorials/681-startup-repair.html

We don't want to use system restore right now though, as the restore files may actually contain the virus. Depending on how sneaky it was.
OK, Its been running the scan for about 35 minutes now, I have used MalwareBytes before and I know what you mean about having to go back and deleting the files because it Quarantines them.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Pavilion g7-1350dx
OS
Windows 7 Ultimate SP1 x64
CPU
AMD A6-3420M APU
Memory
4.0 Gb DDR3 838 MHz
Graphics Card(s)
AMD Radeon HD 6520G
Sound Card
IDT HD Audio
Screen Resolution
1600x 900
Hard Drives
500GB Hitachi HTS547550A9E384
I successfully managed to remove the infected files, I have included the log files, I ran a quick scan first and then a full scan.
View attachment mbam-log-2011-03-31 (20-00-54).txt
Code:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5363

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

3/31/2011 8:00:54 PM
mbam-log-2011-03-31 (20-00-54).txt

Scan type: Quick scan
Objects scanned: 154371
Time elapsed: 3 minute(s), 6 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\fCd16633iHkPb16633 (Trojan.Agent.Gen) -> Value: fCd16633iHkPb16633 -> Quarantined and deleted successfully.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\programdata\fcd16633ihkpb16633\fcd16633ihkpb16633.exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\local settings\temporary internet files\Content.IE5\ZWQ3XI6W\download[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
View attachment mbam-log-2011-03-31 (20-47-25).txt
Code:
Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 6231

Windows 6.1.7600
Internet Explorer 8.0.7600.16385

3/31/2011 8:47:25 PM
mbam-log-2011-03-31 (20-47-25).txt

Scan type: Full scan (C:\|)
Objects scanned: 269605
Time elapsed: 41 minute(s), 23 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 3

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\60IKWZ5T\antispy2011setup[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\N6JD1KBM\antispy2011setup[1].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
c:\Users\basa\AppData\Local\microsoft\Windows\temporary internet files\Low\Content.IE5\N6JD1KBM\antispy2011setup[2].exe (Trojan.Agent.Gen) -> Quarantined and deleted successfully.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Pavilion g7-1350dx
OS
Windows 7 Ultimate SP1 x64
CPU
AMD A6-3420M APU
Memory
4.0 Gb DDR3 838 MHz
Graphics Card(s)
AMD Radeon HD 6520G
Sound Card
IDT HD Audio
Screen Resolution
1600x 900
Hard Drives
500GB Hitachi HTS547550A9E384
Here are a couple of other options in case Malwarebytes doesn't get it out of the system. Even if MB does remove it, it would be a good idea to run your AV or these tools and do a full system scan while disconnected from the net. Once you get a virus, it's hard to tell how much of it is left behind. And unfortunately, even one tiny file can cause it to come back and reinstall.

Microsoft Windows Malicious Software Removal Tool

Download details: Microsoft® Windows® Malicious Software Removal Tool (KB890830) x64

Norton Power Eraser

http://security.symantec.com/nbrt/npe.asp?lcid=1033&origin=default
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell Hell oh Well
OS
Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
CPU
Intel Core 2 Duo 2.93GHz
Memory
Not much with my ADHD
Graphics Card(s)
ATI Radeon HD 4350
Monitor(s) Displays
24" HDTV/Monitor
Screen Resolution
Blurry after a Scotch or 2
Hard Drives
1 HDD 250 GB, 1 HDD 1 TB, 3 - 1 TB Externals
Case
Don't get on my case...man :D
Cooling
I have an Air Conditioner & Diet Pepsi
Keyboard
Saitek Cyborg
Mouse
10 yr old MS optical mouse that still works
Internet Speed
Never fast enough
Antivirus
Various
Browser
Various
Hi ionbasa,

Looks like Malwarebytes did the trick - its very good software.

As an additional check, can I suggest performing an online scan using the ESET on-line scanner? This just helps to give some comfort that nothing has slipped through the cracks.

Regards,
Golden
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Below is courtesy of JACEE!


I just copied and pasted.
You can run it in safe mode with network if needed.
Also when done you can leave the download which is definitions on your PC and next time it will just update definitions and run.
Much quicker if needed again later.
First time I used it was for testing. The second time I was actually doing a virus check as you would be doing.
Saved 5-10 minutes on second run.
Mike


See if Eset finds anything ...

  1. Hold down Control and click on the following link to open ESET OnlineScan in a new window.
    ESET OnlineScan
  2. Click the
    esetOnline.png
    button.
  3. For alternate browsers only: (Microsoft Internet Explorer users can skip these steps)
    1. Click on
      esetSmartInstall.png
      to download the ESET Smart Installer. Save it to your desktop.
    2. Double click on the
      esetSmartInstallDesktopIcon.png
      icon on your desktop.
  4. Check
    esetAcceptTerms.png
  5. Click the
    esetStart.png
    button.
  6. Accept any security warnings from your browser.
  7. Check
    esetScanArchives.png
  8. Push the Start button.
  9. ESET will then download updates for itself, install itself, and begin scanning your computer. Please be patient as this can take some time.
  10. When the scan completes, push
    esetListThreats.png
  11. Push
    esetExport.png
    , and save the file to your desktop using a unique name, such as ESETScan. Include the contents of this report in your next reply.
  12. Push the
    esetBack.png
    button.
  13. Push
    esetFinish.png
 

My Computer

Computer Manufacturer/Model Number
Hopalong/ Godzilla
OS
Windows7 Pro 64bit SP-1; Windows XP Pro 32bit
CPU
Intel Core i7-870 Lynnfield 2.93GHz LGA 1156 95W Quad-Core
Motherboard
ASUS P7P55D-E PRO
Memory
8GB@1400MHz Crucial Ballistix DDR3-1600 4x2GB
Graphics Card(s)
ASUS ENGTX460 DirectCU/2DI/1GD5 1GB 256-bit GDDR5
Sound Card
VIA Onboard
Monitor(s) Displays
Asus VS248H-P 24"; Samsung SyncMaster 941BW 19"ws
Screen Resolution
1920x1080; 1440x900
Hard Drives
Samsung 830 120GB SSD
Intel 320 120GB SSD
Western Digital Caviar Black WD7501AALS 750GB 7200 RPM SATA 3.0Gb/s
Western Digital Caviar Black WD6401AALS 640GB 7200 RPM SATA 3.0Gb/s
PSU
COOLER MASTER Silent Pro RS850-AMBAJ3-US 850W Modular
Case
COOLER MASTER HAF 932 RC-932-KKN5-GP Black
Cooling
Scythe "Mugen-2 Rev.B" (2 ScytheKaze-Jyuni PWM fans)
Keyboard
Logitech K-320
Mouse
Kensington
Antivirus
Avast Inernet Suite
Browser
IE 9 ; Chrome
okay, Thank you for all the help, MB fixed it and than ran eset and all was clean.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
HP Pavilion g7-1350dx
OS
Windows 7 Ultimate SP1 x64
CPU
AMD A6-3420M APU
Memory
4.0 Gb DDR3 838 MHz
Graphics Card(s)
AMD Radeon HD 6520G
Sound Card
IDT HD Audio
Screen Resolution
1600x 900
Hard Drives
500GB Hitachi HTS547550A9E384
Good deal.
 

My Computer

Computer Manufacturer/Model Number
Insane hobo technologies. ;-)
OS
Windows 7 x64
CPU
Intel i7 2600k
Motherboard
Asrock z68 extreme 4 gen 3
Memory
G.skill Ripjaw 16gigs @ 1866
Graphics Card(s)
Nvidia gtx580 (evga)
Sound Card
Integrated HD audio + hdmi
Monitor(s) Displays
24" ASUS widescreen + 42" insignia
Screen Resolution
1080p (1920x1080)
Hard Drives
128 Samsung 830
256 Samsung 840
3 x 1tb storage drive (various)
1 western digital 1tb (eSATA)
1 Seagate 1tb (eSATA)
PSU
1 kilowatt SLI/Crossfire rated Silverstone modular
Case
NZXT Phantom + additional 220 fan
Cooling
Zalmann
Keyboard
Microsoft wireless 3000 (v2)
Mouse
MS - wireless 5000 (bluetrack)
Internet Speed
depends on if you ask me or my provider.
Other Info
The above information is provided as is, and the author assumes no responsibility for issues it may cause with your sanity or fanboyism.
Back
Top