Hi, about 2 years ago I seemed to have been infected with a virus that attacked almost every exe file on my computer, it now seems that I have in fact somehow bloody obtained that same virus once again.
The virus makes almost random hash folders in your drivers such as C:\8GA90J8979H8T7H9\update.exe, first time user of HJT i'm wondering if any pro's would be able to help me determine if this log has any useful info on removing this stubborn badboy of a virus.
Log - http://pastebin.com/f55283796
Sadly AVG doesn't pick up anything at all when I do a Full Scan though I don't understand honestly how this virus just gets around almost everything I try to do to stop it.
Anyways thanks in advance for any help guys.
Thanks,
Aaron.
DO NOT use any TOOLS such as Combofix, SmitfraudFix, MBAM, Vundofix, or HijackThis fixes without supervision.
Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.
Stay with this topic until I give you the all clean post.
You might want to print these instructions out.
I suggest you do this:
Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab. Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders." Uncheck "Hide protected operating system files."
Click Apply, and then click OK.
Please do not delete anything unless instructed to.
Please download ATF Cleaner by Atribune. Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.
Next:
Please download Malwarebytes' Anti-Malware to your desktop.
Double-click mbam-setup.exe and follow the prompts to install the program.
At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
If an update is found, it will download and install the latest version.
Once the program has loaded, select Perform quick scan, then click Scan.
When the scan is complete, click OK, then Show Results to view the results.
Be sure that everything is checked, and click Remove Selected.
When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Please don't attach the scans / logs, use "copy/paste".
I ran SUPERAntiSpyware it took about an hour to complete the scan, though when it had finished it just prompted me with a message saying "No malicious software found" so obviously then there was no Notepad log that appeared.
I also ran ATF Cleaner though nor did that seem to do anything at all either. I had selected all the boxes in ATF Cleaner and then "Emptied Selected" it prompted me with a small box saying "Done Cleaning!! ATF Cleaner has freed 120.777MBs"
Here is the new HiJackThis log as you requested also, http://pastebin.com/f70fde735
As a side note, some strange folder has now appeared in my C: it seems similar to the virus considering it looks like it's using some sort of Hash looking folder name "a372c413d64a042862cc342a"
Inside the folder there are 2 Sub folders, "amd64" & also "i386"
You also requested that I describe how my computer is behaving at the moment, it seems to be running quite well in fact to be honest it feels like the virus has no infected anything at all.
Last time I had this virus it completely infected 95% of the exe's on my computer nothing would be able to open I lost over 400 gig of Movies/TV Series, i now have 800+ gig of those same Movies/TV Series and i'm not exactly looking forward to having to do a complete format again including every drive that has ever been plugged into my computer.
Though as I said, it doesn't seem to be reacting with my computer at all really so my computer is behaving quite well.
Thanks once again in advance and for all your help so far.
Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. Note: If you are having difficulty properly disabling your protective programs, or are unsure as to what programs need to be disabled, please refer to the information available through this link : Protective Programs
Double click on ComboFix.exe & follow the prompts.
Note: Combofix will run without the Recovery Console installed.
As part of it's process, ComboFix will check to see if the Microsoft Windows Recovery Console is installed. With malware infections being as they are today, it's strongly recommended to have this pre-installed on your machine before doing any malware removal. It will allow you to boot up into a special recovery/repair mode that will allow us to more easily help you should your computer have a problem after an attempted removal of malware.
Follow the prompts to allow ComboFix to download and install the Microsoft Windows Recovery Console, and when prompted, agree to the End-User License Agreement to install the Microsoft Windows Recovery Console.
**Please note: If the Microsoft Windows Recovery Console is already installed, ComboFix will continue it's malware removal procedures.
[external image: Posted Image]
Once the Microsoft Windows Recovery Console is installed using ComboFix, you should see the following message:
[external image: Posted Image]
Click on Yes, to continue scanning for malware.
When finished, it shall produce a log for you. Please include the C:\ComboFix.txt in your next reply.
"copy/paste" a new HijackThis log file into this thread as well.
Notes:
1.Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. ComboFix may reset a number of Internet Explorer's settings, including making I-E the default browser.
3. Combofix prevents autorun of ALL CD, floppy and USB devices to assist with malware removal & increase security. If this is an issue or makes it difficult for you – please tell your helper.
4. CF disconnects your machine from the internet. The connection is automatically restored before CF completes its run. If CF runs into difficulty and terminates prematurely, the connection can be manually restored by restarting your machine.
Give it atleast 20-30 minutes to finish if needed.
Please don't attach the scans / logs, use "copy/paste".
Also please describe how your computer behaves at the moment.