Dear Helpers,
Recently my computer was infected with some kind of Trojan, in which a small banner will popup every 5 minutes or so which says: THIS COMPUTER IS BEING ATTACKED". (The Banner has a star wand on it).
I've tried to search through the processes in task manager and manage to find the processes which is global.exe, system.exe and svchost.exe. They are found in dllcache\recycler (which i rename and deleted it for few times, but after a few minutes they reappear again, and till now I'm not able to determine the root of the cause of these processes).
Can any one help me to remove this malware? Thank you very much.
Best Regards,
Lexxie.
I've followed your instructions in downloading the combofix.exe software and rename it as ABCD.exe before downloading it to my desktop. However, when i start the application it states that the software has been compromised and there'sa virus call virut will enter my computer.
Then the program is no more there.
Please shed some light on this. Thank you very much
You are infected with a polymorphic file infector.
This infection can and will infect all the machine's executable files .exe, .scr, .rar, .zip, .htm, .html.
you should be aware that you may have been infected by a backdoor trojan. This type of program has the ability to steal passwords and other information from your system. If you are using your computer for sensitive purposes such as internet banking then I recommend you take the following steps immediately:
Use another, uninfected computer to change all your internet passwords, especially ones with financial implications such as banks, paypal, ebay, etc. You should also change the passwords for any other site you use.
Call your bank(s), credit card company or any other institution which may be affected and advise them that your login/password or credit card information may have been stolen and ask what steps to take with regard to your account.
Consider what other private information could possibly have been taken from your computer and take appropriate steps
the best thing you can do is to backup, preferably to CD, all your important data, documents, pictures, movies, and songs.
DO NOT backup any applications or installers and DO NOT backup any files with the following extensions:
•.exe
•.scr
•.htm
•.html
•.xml
•.zip
•.rar
Download Dr.Web CureIt to the desktop:
ftp://ftp.drweb.com/pub/drweb/cureit/drweb-cureit.exe
Doubleclick the drweb-cureit.exe file and Allow to run the express scan
This will scan the files currently running in memory and when something is found, click the yes button when it asks you if you want to cure it. This is only a short scan.
Once the short scan has finished, mark the drives that you want to scan.
Select all drives. A red dot shows which drives have been chosen.
Click the green arrow at the right, and the scan will start.
Click 'Yes to all' if it asks if you want to cure/move the file.
When the scan has finished, in the menu, click file and choose save report list
Save the report to your desktop. The report will be called DrWeb.csv
The report is too long, I'm not able to upload to this post. However the scanned result is as shown below::
—————————————————————————–
Scan statistics
—————————————————————————–
Scanned: 6228
Infected: 2
Modifications: 0
Suspicious: 0
Adware: 0
Dialers: 0
Jokes: 0
Riskware: 0
Hacktools: 0
Cured: 0
Deleted: 2
Renamed: 0
Moved: 0
Ignored: 0
Scan speed: 5823 Kb/s
Scan time: 00:04:39
—————————————————————————–
After I tried with Dr. Web CureIt, the virus is still in the computer, When I run D.r Web CureIt again, the same virus was detected.
How my computer behaves, as follows:
Actually the problem arises when some of my programmes are not functioning. Most probably infected by a Trojan. Then it has a pop up banner which states "THIS COMPUTER IS BEING ATTACKED" - A blue coloured banner moving diagonally with a wand at its side.
Some of my folders on desktop and in my documents folders are all turned into application (.exe) file and alot of my data lost.
Vista users: 1. These tools MUST be run from the executable. (.exe)
2. With Admin Rights (Right click, choose "Run as Administrator") every time you run them
1) exeHelper
Please download exeHelper to your desktop.
Double-click on exeHelper.com to run the fix.
A black window should pop up, press any key to close once the fix is completed.
Post the contents of log.txt (Will be created in the directory where you ran exeHelper.com) Note: If the window shows a message that says "Error deleting file", please re-run the program before posting a log - and post the two logs together (they will both be in the one file).
I HAVE RUN THE APPLICATION FOR 3 TIMES BECAUSE I DON'T SEE ANY DELETION OF .EXE FILES:
PLEASE HELP ME ON THIS MATTER, THANK YOU VERY MUCH!
exeHelper by Raktor
Build 20091021
Run at 12:53:18 on 11/17/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
exeHelper by Raktor
Build 20091021
Run at 12:53:48 on 11/17/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–
exeHelper by Raktor
Build 20091021
Run at 12:54:27 on 11/17/09
Now searching…
Checking for numerical processes…
Checking for bad processes…
Checking for bad files…
Checking for bad registry entries…
Resetting filetype association for .exe
Resetting filetype association for .com
Resetting userinit and shell values…
Resetting policies…
–Finished–