Jump to content

Build Theme!
  •  
  • Infected?

big grin WE'RE SURE THAT YOU'LL LOVE US!

We invite you to ask questions, share experiences, and learn. It's 100% free. Did we mention that it's free. It is. It's free. Join 91520 other members! Anybody can ask, anybody can answer. Consistently helpful members with best answers are invited to staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Screwed up with a virus or malware.... [Closed]


  • This topic is locked This topic is locked
7 replies to this topic

#1 rozermartin

rozermartin

    Guest

  • Guests
  • Pip
  • 17 posts

Posted 28 December 2013 - 03:51 AM

Hello everyone.

 

 

I am in a severe problem as my computer has just been infected and the virus is not even detectable through antivirus programs. I have an updated Kasperksy Antivirus 2014 and a malwarebytes software on my system. Still the virus is undeletable.

 

 

I have attached an image for the infection on my system. The one named as Microsoft. As many times I delete it it just comes back and makes more and more copies of my every folder and file on the system. It has been stalking over my mind and slowing down my pc like hell. Please help....


    Advertisements

Register to Remove


#2 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,250 posts
  • Interests:LFC, music, more LFC, more music

Posted 28 December 2013 - 08:44 AM

Hello rozermartin and welcome to the WTT forum.

My name is Satchfan and I would be glad to help you with your computer problem.

Please read the following guidelines which will help to make cleaning your machine easier:

  • please follow all instructions in the order posted
  • please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear
  • all logs/reports, etc. must be posted in Notepad. Please ensure that word wrap is unchecked. In Notepad click Format, uncheck Word wrap if it is checked
  • if you don't understand something, please don't hesitate to ask for clarification before proceeding
  • the fixes are specific to your problem and should only be used for this issue on this machine.
  • please reply within 3 days. If you do not reply within this period I will post a reminder but topics with no reply in 4 days will be closed!

IMPORTANT:

Please DO NOT install/uninstall any programs unless asked to.
Please DO NOT run any scans other than those requested


Run RogueKiller

IMPORTANT: Please remove any usb or external drives from the computer before you run this scan!

Close all running programs.


Download one of these to your desktop:



for a 32-bt system download this version.
for 64-bit use this one

.

  • close all running programs
  • for Windows Vista/Seven, right click -> run as administrator, for XP simply double-click on RogueKiller.exe
  • when the pre-scan is finished, click on Scan
  • click on Report and copy/paste the content in your next post
  • NOTE: DO NOT attempt to remove anything that the scan detects –everything that is reported is not necessarily bad

If the program is blocked, continue to try it several times. If it still doesn’t work, (it could happen), rename it to winlogon.exe.

Please post the contents of the RKreport.txt in your next reply.

Satchfan

 

 


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#3 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,250 posts
  • Interests:LFC, music, more LFC, more music

Posted 30 December 2013 - 03:02 AM

Hi rozermartin

 

It has been a couple of days since I replied to your request for help with your computer problems.

 

Please let me know if you are having problems and still need help.

 

Thanks

 

Satchfan


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#4 rozermartin

rozermartin

    Guest

  • Guests
  • Pip
  • 17 posts

Posted 31 December 2013 - 01:29 AM

I was not able to reply due to your Forum regulation.



#5 rozermartin

rozermartin

    Guest

  • Guests
  • Pip
  • 17 posts

Posted 31 December 2013 - 01:43 AM

Following below is test problem.
 
RogueKiller V8.8.0 [Dec 27 2013] by Tigzy
mail : tigzyRK<at>gmail<dot>com
Feedback : http://www.adlice.com/forum/
Website : http://www.adlice.co...es/roguekiller/
Blog : http://www.adlice.com

Operating System : Windows 7 (6.1.7601 Service Pack 1) 32 bits version
Started in : Normal mode
User : SEO [Admin rights]
Mode : Scan -- Date : 12/31/2013 13:10:23
| ARK || FAK || MBR |

¤¤¤ Bad processes : 0 ¤¤¤

¤¤¤ Registry Entries : 3 ¤¤¤
[PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:8555;hxxps=127.0.0.1:8555 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ DESK][PUM] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Scheduled tasks : 1 ¤¤¤
[V2][SUSP PATH] iolo System Checkup : C:\ProgramData\iolo\scustask.lnk - /toaster [-] -> FOUND

¤¤¤ Startup Entries : 0 ¤¤¤

¤¤¤ Web browsers : 0 ¤¤¤

¤¤¤ Browser Addons : 0 ¤¤¤

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver : [NOT LOADED 0xc0000033] ¤¤¤

¤¤¤ External Hives: ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
--> %SystemRoot%\System32\drivers\etc\hosts




¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: (\\.\PHYSICALDRIVE0 @ IDE) ST3160316AS ATA Device +++++
--- User ---
[MBR] bbbaa754edad842bfd49fce534d918ea
[BSP] cd27ed3eb96aab5c994ff939e1f9cca6 : Windows 7/8 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 2048 | Size: 100 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 206848 | Size: 79900 Mo
2 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 163842048 | Size: 72624 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[0]_S_12312013_131023.txt >>



 
 


#6 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,250 posts
  • Interests:LFC, music, more LFC, more music

Posted 31 December 2013 - 03:38 AM

Hi Rozermartin

Sorry that you had problems replying but you seem to be OK with that now.

I need you to explain exactly what problem you are having and what suggests that it is a virus.


If you are not intentionally using a proxy server, please do the following:

Run RogueKiller

IMPORTANT: Do not reboot your computer if at all possible otherwise the malware will reactivate and you will have to run RogueKiller again

  • close all programs
  • double-click RogueKiller.exe - Windows 7: right-click the program and select Run as Administrator'
  • after it has completed it's prescan, click on Scan
  • click on the click on the “Proxy” tab
  • make sure only this entry is checked (remove the check marks from the others):


    [PROXY IE][PUM] HKCU\[...]\Internet Settings : ProxyServer (hxxp=127.0.0.1:8555;hxxps=127.0.0.1:8555 [Country: (Private Address) (XX), City: (Private Address)]) -> FOUND
     

  • click on Fix Proxy button.

When you’ve done that, please run RogueKiller, (RK), again and send a new log.

Before I ask for more scans I need to know what we are looking for so when you send the RK log, please explain the problem.

Thanks

Satchfan

 


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#7 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,250 posts
  • Interests:LFC, music, more LFC, more music

Posted 03 January 2014 - 03:54 AM

Hi rozermartin

 

It has been a few days since I replied to your request for help with your computer problems.

 

Please let me know if you are having problems and still need help.

 

Thanks

 

Satchfan


NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

#8 Satchfan

Satchfan

    SuperHelper

  • Malware Team
  • 6,250 posts
  • Interests:LFC, music, more LFC, more music

Posted 04 January 2014 - 04:12 PM

Due to inactivity this topic will be closed.
If you need help please start a new thread.

New members follow the instructions here http://forums.whatth...ed_t106388.html and start a new topic

NINA - Proud graduate of the WTT Classroom

Member of UNITE

The help you receive here is free but if you feel I have helped, you may consider making a Donation.

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users