This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] unknown virus infection

11 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I am sorry for taking so long to reply in the previous thread. I will be more prompt this time. The previous thread is here

http://forums.whatthetech.com/Unknown_Viru…on_t106273.html

I tried repairing the connections (both the wireless and the LAN) and got the following error messages

For the LAN; "Windows could not finish repairing the problem because the following action cannot be completed: Failed to query TCP/IP settings of the connection. Cannot proceed. For assistance, contact the person who manages your network."

For the Wireless; "Windows could not finish repairing the problem because the following action cannot be completed: Connecting to the wireless network. For assistance, contact the person who manages your network."

I am the one who manages my own network and I cannot see any problem with the network itself. Both my desktop and my wife's laptop connect without a problem so I am unsure what the problem could be.

I apreciate any help you can provide.

Thanks.
Please copy the entire contents of the codebox below into Notepad:
  • Open Notepad
  • Copy the contents of the codebox below using CTRL C

REGEDIT4

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Winsock]

[-HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WinSock2]

  • Now return to Notepad and use CTRL V to paste the script
  • Verify that you have pasted the complete script
  • Save the Notepad file to your Desktop as FixReg.reg using Save as Type: All files
  • Locate FixReg.reg on your desktop
  • Double click to run, and when prompted Allow the file to merge with your registry
  • OK your way out.
After that, Reboot your computer.


After the reboot, we will reinstall TCP/IP
  • Go to Start the Settings and choose Network Connections
  • Right click on your normal connection icon, and choose Properties
  • Click the Install button
  • Choose Protocol then click Add
  • Click Have disk
  • In the drop down box, type in: C:\WINDOWS\INF and click OK
  • In the next dialog, click Internet Protocol (TCP/IP) then click OK
  • Click Close to leave the properties box
After that, Reboot your computer and see if you have regained your connection.
Unfortunately my connection is still unfunctional. I tried repairing the connections but got the same error messages as before. Still no connection on either the wireless nor the LAN. Please advice. Thanks.
Go to Network Connections, right click on the icon and click Properties.
Look for WinPK Filter Driver, or something named very similar, select it, and click Uninstall
Repeat this for both of your network connections, and then reboot and try again.
Ok, that did it. I uninstalled the driver on the LAN connection and it was not there when I went to the wireless. I rebooted and I now have a connection again. What other logs do you need to work on the virus problem or to verify that this computer is clean now?
Oh wow, I just saw you lurking and realised I completely lost this log! You should have PMed me to remind me. :blush:

1) MBAM
Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.

2) ESET
You can use either Internet Explorer or Mozilla FireFox for this scan.

  • Please go here then click on: [external image: Posted Image]

    Note: If using Mozilla Firefox you will need to download esetsmartinstaller_enu.exe when prompted then double click on it to install.
    All of the below instructions are compatible with either Internet Explorer or Mozilla FireFox.

  • Select the option YES, I accept the Terms of Use then click on: [external image: Posted Image]
  • When prompted allow the Add-On/Active X to install.
  • Make sure that the option Remove found threats is NOT checked, and the option Scan archives is checked.
  • Now click on Advanced Settings and select the following:
    • Scan for potentially unwanted applications
    • Scan for potentially unsafe applications
    • Enable Anti-Stealth Technology
  • Now click on: [external image: Posted Image]
  • The virus signature database… will begin to download. Be patient this make take some time depending on the speed of your Internet Connection.
  • When completed the Online Scan will begin automatically.
  • Do not touch either the Mouse or keyboard during the scan otherwise it may stall.
  • When completed select Uninstall application on close if you so wish, make sure you copy the logfile first!
  • Now click on: [external image: Posted Image]
  • Use notepad to open the logfile located at C:\Program Files\ESET\EsetOnlineScanner\log.txt.
  • Copy and paste that log as a reply to this topic.

3) What You Will Need To Post:
  • MBAM log
  • ESET log
Lol, I guess I took the "Please do not PM me for malware removal assistance" line in your signature a little too seriously. Here are the two logs you requested. Malwarebytes' Anti-Malware 1.41 Database version: 2857 Windows 5.1.2600 Service Pack 3 9/24/2009 10:21:29 PM mbam-log-2009-09-24 (22-21-29).txt Scan type: Quick Scan Objects scanned: 166292 Time elapsed: 13 minute(s), 21 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 1 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\NDISRD (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: C:\WINDOWS\0535251103110107106.uio (Worm.KoobFace) -> Quarantined and deleted successfully. ESETSmartInstaller@High as CAB hook log: OnlineScanner.ocx - registred OK # version=6 # iexplore.exe=8.00.6001.18702 (longhorn_ie8_rtm(wmbla).090308-0339) # OnlineScanner.ocx=1.0.0.6050 # api_version=3.0.2 # EOSSerial=69dd4bbf96fad840a7a4a2d79aebe157 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=true # antistealth_checked=true # utc_time=2009-09-25 08:31:19 # local_time=2009-09-25 02:31:19 (-0700, Mountain Daylight Time) # country="United States" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # scanned=209926 # found=6 # cleaned=0 # scan_time=6643 C:\mavj.exe a variant of Win32/Cimag.AQ trojan 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\FraudMalwareDefender.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondesdn1.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\Virtumondesdn3.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy\Recovery\WinVirutmtt1.zip Win32/Bagle.gen.zip worm 00000000000000000000000000000000 I C:\Qoobox\Quarantine\C\WINDOWS\system32\scecli.dll.vir a variant of Win32/Kryptik.YQ trojan 00000000000000000000000000000000 I Unfortunately it seems my comp is still infected. :(
The forum really doesn't want to notify me of your replies……… it must have something against you.

Delete this file C:\mavj.exe.
All the other files are in quarantine. Are you still experiencing any issues?
Lol, story of my life. I have deleted the file. My comp starts up quite slow and it runs slow while browsing, particularly with IE. It seems to be a bit faster while browsing with Opera so that is what I am using mostly now. If all else looks clean then I will call it good and notify my internet provider so they can tell me if they see any more suspicious activity during the daytime when no one is using the computer. Thank You for your assistance.
For a bit of a speed up….

1) TFC
Please download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should reboot your machine, if not, manually reboot to ensure a complete clean

2) chkdsk
  • Close any open windows.
  • Go to the Start Menu, Run, type in cmd.exe
  • In the command window that appears, type chkdsk /r, and press enter
  • Agree to any prompts - then reboot the computer.
  • chkdsk should run as you boot the machine up - this will check the harddrive for damaged sectors and attempt to repair them.

3) Defrag
  • Close any open windows.
  • Go to the Start Menu, Programs, Accessories, System Tools, Defrag
  • Defrag all drives in the Disk Defragmenter

Time for some housekeeping
  • Click START then RUN
  • Now type Combofix /u in the runbox and click OK
  • [external image: Posted Image]
The above procedure will reset your System Restore and clear out the backups and quarantines created during the course of this fix.

How to reduce your chances of infection in the future

Web Browsers
Internet Explorer does come pre-installed with all Windows machines - but this doesn't necessarily mean you have to use it! Because it is the most widely used browser, it is targeted by more malware writers, making you more susceptible to infection. There are many other free alternatives out there that offer better security, take one of these for a spin and see if it takes your fancy.
Mozilla Firefox
Google Chrome
Opera

WOT - Web of Trust, warns you about risky websites that try to scam visitors, deliver malware or send spam. Protect your computer against online threats by using WOT as your front-line layer of protection when browsing or searching in unfamiliar territory. WOT's color-coded icons show you ratings for 21 million websites, helping you avoid the dangerous sites:
Green to go
Yellow for caution
Red to stop
WOT has an addon available for both Firefox and Internet Explorer.

If you are too attached to leave Internet Explorer, follow these additional steps to make the browser more secure.
  • From within Internet Explorer click on the Tools menu and then click on Options.
  • Click once on the Security tab.
  • Click once on the Internet icon so it becomes highlighted.
  • Click once on the Custom Level button.
    • Change the Download signed ActiveX controls to Prompt.
    • Change the Download unsigned ActiveX controls to Disable.
    • Change the Initialise and script ActiveX controls not marked as safe to Disable.
    • Change the Installation of desktop items to Prompt.
    • Change the Launching programs and files in an IFRAME to Prompt.
    • Change the Navigate sub-frames across different domains to Prompt.
  • When all these settings have been made, click on the OK button.
  • If it prompts you as to whether or not you want to save the settings, press the Yes button.
Additional Security Measures
Keep your software up-to-date - You should be manually performing updates of your software once a week to ensure that you are current with anti-virus definitions and patched for any security vulnerabilities. This does not just apply to your anti-virus/anti-malware software; malware authors rely on exploiting commonly used software such as Java and Adobe Reader, which need to be kept up to date as well.

Keep Windows up-to-date - Use Windows Update regularly to stay current with security patches and service packs.

MVPS Hosts File - This custom hosts file effectively blocks a wide range of unwanted ads, banners, 3rd party Cookies, 3rd party page counters, web bugs, and many hijackers.

Firewalls - Without a firewall your computer is susceptible to being hacked and taken over. If you use the Windows Firewall you might think that's sufficient - but it only controls one way of the traffic (inbound). Simply using a Firewall in its default configuration can lower your risk greatly.

What Not To Do
The Perils of P2P File Sharing - Even if a P2P application is on the 'safe' list, malware can still be downloaded through infected files - executables, zip files and even MP3s. It is just not worth the risk.

Fake Security/Optimization Software - Be very wary with any security software that is advertised in popups or in other ways. They are not only usually of no use, but often have malware in them.

Additional Reading
How to prevent Malware - I strongly recommend that you read Miekiemoses' good advice

Please reply to this thread once more if you are satisfied so that we can mark the problem as resolved.
I have run the programs you suggested. I seem to be having an additional problem however. My comp is restarting on its own each night. I keep getting the notification icon that tells me I have updates ready to be installed. I install the updates and restart my computer but I get the icon again and it has the same updates trying to install again. I have left my comp running at night the last few days and it seems the updates auto install and restart my comp but when I log back in the same updates are still ready to be installed. Please let me know of any suggestions to solve this. Thanks.
  • Please download Dial-A-Fix from one of the following mirrors:
  • Extract the zip file to your desktop.
  • Double click Dial-a-Fix.exe to start the program.
  • Press the green double checkmark box (Looks like this: [external image: Posted Image])
  • UNcheck Empty Temp Folders, as well as Adjust Time/Date in the prep section. The prep section should then look like this:

    [external image: Posted Image]

    [external image: Posted Image]
  • Click on go
  • Exit/Close Dial-A-Fix

Next please go to windows update and install all critical updates

http://www.windowsupdate.com

Reboot, and see if that solves your update issues.
Did what you asked but I still have the same problem. The updates that seem to still need to be installed are a security update and September's malicious removal tool. I am not sure this information is pertinent but there it is anyway. Let me know what else I should I try. Thanks
Sorry Rob, I'm out of ideas from the malware front. You are clean of malware, so this is leaving us with a software problem. Head over to our Windows Forums and post a topic there if the issue is still remaining. Thanks for your patience.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI