This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Suspected Recurring Malware Infection

8 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I was told to post here by Ztruker in this thread

Run Time Error

I restarted the computer and an error popped up with "mikasova". i went to msconfig, unchecked something called "ferizokey" which had the command "mikasova.dll".

I did that twice and now their gone.

There's still another called ferizokey but thats unchecked and there's no problems. that has a command "gedesumi.dll"

I've just checked msconfig and there's another thing called "ferizokey" which is currently still checked.

Not sure what else to say, hope you can help.

Thanks
[external image: Posted Image]


DO NOT use any TOOLS such as Combofix, SmitfraudFix, MBAM, Vundofix, or HijackThis fixes without supervision.

Doing so could make your pc inoperatible and could require a full reinstall of your OS, losing all your programs and data.


Vista users:
1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator")


Stay with this topic until I give you the all clean post.

You might want to print these instructions out.

I suggest you do this:

Double-click My Computer.
Click the Tools menu, and then click Folder Options.
Click the View tab.
Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.


Please do not delete anything unless instructed to.


Please download ATF Cleaner by Atribune.
Download - ATF Cleaner»
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
[external image: Posted Image]
Click the Empty Selected button.

(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)

It's normal after running ATF cleaner that the PC will be slower to boot the first time or two.

Next:

Please download Malwarebytes' Anti-Malware to your desktop.

  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan.
    [external image: Posted Image]
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected .
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
  • Note: If you receive a notice that some of the items couldn't be removed, that they have been added to the delete on reboot list, please reboot.
Also "copy/paste" a new HijackThis log file into this thread.

Also please describe how your computer behaves at the moment.


Please don't attach the scans / logs, use "copy/paste". .
Thanks for the help. Just a few questions before starting.

Theirs nothing on the desk top or in programs that's called "My Computer"

I already have ATF Cleaner installed do i need to download and upgrade?

Before starting should i download HijackThis?

Also i'm not sure if you read the thread in the first post but i'm having this problem as well

when i log out and go to the users page (3 of us use the pc) it goes to black before you can do anything.

The pc's shutting down fine, just this little problem


Will this be fixed by the above? i'm worried this will take too long and i won't be able to do a System Restore as Ztruker suggested before the infection. I'm wondering if there's only so many days to do a restore in.

I hope that's understandable, i'm not great with tech speak :blush:
Have a look at SR and see what dates are available. 1. Click Start. 2. Point to All Programs. 3. Point to Accessories. 4. Point to System Tools. 5. Click System Restore. 6. Follow the instructions on the wizard. See if you can find a date the the PC worked.
The earliest one is 10/9/2009 20:11:38 Judging from when i know the problem started and because it tells me i downloaded Systweak Registry Cleaner on 12/9/2009 20:37:45 i'd say 11/9/2009 12:02:52
Logging in and out is back to normal. I went to msconfig and all these are gone. "ferizokey" "mikasova.dll". gedesumi.dll" Straight after reboot logging in and overall the pc was slow but it seems fine now. Do i still need to do the above or am i clear?
Ok mate. Theirs nothing on the desk top or in programs that's called "My Computer" I already have ATF Cleaner installed do i need to download and upgrade? Before starting should i download HijackThis?
Click Start > see the "My Computer" icon?
Right Click on the "My Computer" icon and select Show on Desktop.

We won't need HijackThis, just the MBAM san results.
Sorry mate, might just me being tired but…

I now have a computer icon, double clicked. It's showing me disc space with folders on the left but i can't find

Uncheck "Hide file extensions for known file types."
Under the "Hidden files" folder, select "Show hidden files and folders."
Uncheck "Hide protected operating system files."
Click Apply, and then click OK.

:lol: ok mate here goes Malwarebytes' Anti-Malware 1.41 Database version: 2794 Windows 6.0.6001 Service Pack 1 14/09/2009 01:16:57 mbam-log-2009-09-14 (01-16-57).txt Scan type: Quick Scan Objects scanned: 94904 Time elapsed: 6 minute(s), 13 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 1 Registry Values Infected: 1 Registry Data Items Infected: 3 Folders Infected: 4 Files Infected: 9 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\seekeen (Trojan.Agent) -> Quarantined and deleted successfully. Registry Values Infected: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ce953ef951abfdcd808bfc6a09e799d2 (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. Registry Data Items Infected: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Folders Infected: C:\Program Files\A360 (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\Protection System (Rogue.ProtectionSystem) -> Quarantined and deleted successfully. C:\Program Files\Seekeen (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\VJones\AppData\Roaming\Microsoft\Windows\Start Menu\A360 (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. Files Infected: C:\Windows\Temp\VRT7FB0.tmp (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Program Files\Seekeen\home.js (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\Seekeen\readme.html (Trojan.Agent) -> Quarantined and deleted successfully. C:\Program Files\Seekeen\uninstall.exe (Trojan.Agent) -> Quarantined and deleted successfully. C:\Users\VJones\AppData\Roaming\Microsoft\Windows\Start Menu\A360\A360.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. C:\Users\VJones\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Help.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. C:\Users\VJones\AppData\Roaming\Microsoft\Windows\Start Menu\A360\Registration.lnk (Rogue.A360AntiVirus) -> Quarantined and deleted successfully. C:\Program Files\Common Files\System\Uninstall\Uninstall A360.lnk (Rogue.AV360) -> Quarantined and deleted successfully. C:\Users\VJones\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\A360.lnk (Rogue.AntiVirus360) -> Quarantined and deleted successfully. EDIT: Computer went a little slow on reboot

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI