Author Topic: Great...I have a virus. Please help.  (Read 5429 times)

0 Members and 1 Guest are viewing this topic.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Great...I have a virus. Please help.
« on: July 13, 2009, 05:40:36 AM »
Hi.

I have a Toshiba laptop running XP.

I downloaded a virus, and I'm not sure what to do.  I have AVG and it deleted some spyware junk, but didn't detect any viruses.  I then ran BitDefender and it detected 5 viruses, and supposedly deleted them. 

My dvd drive isn't detected, so I can't even reformat (which I would have only done as a last resort anyway).

I deleted the file that I believe contained the virus.

What should I do?  I'm not sure what info you need, but please inform me how to give you whatever info you need.

Thank you so much.

Offline Eric the Red

  • ISO/IEC 27001:2005
  • Administrator
  • Hero Member
  • *****
  • Posts: 1611
  • Would somebody please pass me a beer!
Re: Great...I have a virus. Please help.
« Reply #1 on: July 13, 2009, 07:02:58 AM »
Hi Woody189,

Welcome back. Is this the same Toshiba that had the virus back in April of this year? Are you able to tell us what BitDefender reported as having been detected? Please follow the directions shown below and supply the information requested, also, we would prefer it if you don't go off and do your own thing without telling us - thre are a lot of snake oil salesmen out there on the net.

Please download ATF Cleaner by Atribune from http://www.atribune.org/index.php?option=com_content&task=view&id=25&Itemid=25 .  Save it to your Desktop.

Run ATF Cleaner
  • Double-click ATF-Cleaner.exe to run the program.
  • Click Select All found at the bottom of the list.
  • Click the Empty Selected button.
  • Click Exit on the Main menu to close the program.
  • Shutdown/restart the computer.
Next Please download Malwarebytes' Anti-Malware to your desktop.
  • Double-click mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform full scan, then click Scan.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad.


Please save it to a convenient location.
The log can also be found here: C:\Documents and Settings\Username\Application Data\Malwarebytes\Malwarebytes' Anti-Malware\Logs\log-date.txt
  • Please post contents of that file in your next reply.
"The time to start running is around about the "e" in "Hey, you!" "
Proud member Since 2004 

The information I provide is provided "AS IS" without warranty, and confers no rights.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #2 on: July 13, 2009, 08:01:52 AM »
Hello Eric.  Yes same comp.  I never resolved the previous problem.  A friend of mine got it running, but I stopped using it.  I recently began using it again.

I don't recall what the Bitdefender said.  I ran the ATF Cleaner already, but I did it again.  I was in the process of doing a quick scan w/ the Malaware, but I canceled it to run a full scan. I will post results when I get them.

Thanks.

Offline GR@PH;<'S

  • Administrator
  • Hero Member
  • *****
  • Posts: 15651
    • http://www.taktmobiles.co.uk
Re: Great...I have a virus. Please help.
« Reply #3 on: July 13, 2009, 10:35:05 AM »
woody189,
It is always best to carry on posting till your PC is all clear as that way we know it is clean not only is it in your interest but it can ofern help other who come here for help

GR@PH;<'S   :Hammys pint:
press Enter then have a Brandy then if the problem is still there have another Brandy
Q: does it work
A: It does seem to for a few hours at least.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #4 on: July 13, 2009, 11:21:44 AM »
You got it.  I'll let you know.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #5 on: July 13, 2009, 04:18:26 PM »
I THINK it worked.  Here's the log in case you're still interested:

Malwarebytes' Anti-Malware 1.38
Database version: 2414
Windows 5.1.2600 Service Pack 3

7/13/2009 7:19:49 AM
mbam-log-2009-07-13 (07-19-41).txt

Scan type: Full Scan (C:\|)
Objects scanned: 162830
Time elapsed: 45 minute(s), 18 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 3
Registry Values Infected: 1
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_CURRENT_USER\SOFTWARE\Cognac (Rogue.Multiple) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\XML (Trojan.FakeAlert) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\ColdWare (Malware.Trace) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Cognac (Trojan.FakeAlert) -> No action taken.

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\WINDOWS\Tasks\{5B57CF47-0BFA-43c6-ACF9-3B3653DCADBA}.job (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\Tasks\{783AF354-B514-42d6-970E-3E8BF0A5279C}.job (Trojan.Downloader) -> No action taken.



I have a question though.  Why is it that Bitdefender didn't find/remove all the viruses, and Malware did? IS it just because Malare is a better program, or because Bit as just online or what?  Just wondering.

thanks again.

Offline winchester73

  • Administrator
  • Hero Member
  • *****
  • Posts: 5125
  • Half a bubble off plumb
Re: Great...I have a virus. Please help.
« Reply #6 on: July 13, 2009, 06:05:37 PM »
Quote
Why is it that Bitdefender didn't find/remove all the viruses, and Malware did?


"No action taken"

You have tell MBAM to remove what it finds.  You'll want to update it first, you are a couple definitions behind.
Speak softly, but carry a big Winchester ... Winchester Arms Collectors Association member



Offline Aaron Hulett [MSFT]

  • Web Server Manager
  • Administrator
  • Hero Member
  • *****
  • Posts: 1098
  • I take the bus!
    • Microsoft Corporation
Re: Great...I have a virus. Please help.
« Reply #7 on: July 13, 2009, 08:12:41 PM »
From your other thread:  "I got it to reformat my whole harddrive.  I backed everything I needed up, so it's not that bad of a thing."

Unless the backup includes infected files.

Once the machine is infected, anything pulled off of it at that point is suspect.  If you did carry out the format, before you brought files back in from the backup, were they scanned first, or at a minimum, was there some form of real-time antimalware protection keeping an eye on things?  In any case, even with these practices, the files are still suspect.  Proceed with caution when pulling files from this fileset.

//A
Aaron Hulett | Malware Protection Center | Microsoft Corporation
This post is provided "AS IS" without warranty, and confers no rights.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #8 on: July 13, 2009, 10:00:33 PM »
Things aren't good after all.

I THOUGHT it worked, but it didn't.

When I rebooted it again, there was no DVD drive detected again.  Also, sometimes when I try to open a programs, they won't open.  For example, if I try to open firefox, then the hourglass will show up, but it won't open.  Same goes for a lot programs.  Most of the times it works, but other times it doesn't

I didn't realize it said NO ACTION TAKEN. 

At the end, I checked off all infected files, and then removed them.  It said that they were in fact removed.  I'm confused.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #9 on: July 13, 2009, 10:13:06 PM »
Oh, and I only kept some important emails and old documents. 

No music, programs, vids, or anything downloaded.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #10 on: July 13, 2009, 10:47:35 PM »
I ran another full scan.

Results:
Malwarebytes' Anti-Malware 1.38
Database version: 2414
Windows 5.1.2600 Service Pack 3

7/13/2009 6:46:32 PM
mbam-log-2009-07-13 (18-46-32).txt

Scan type: Full Scan (C:\|)
Objects scanned: 162786
Time elapsed: 41 minute(s), 38 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 0

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
(No malicious items detected)


Oh man.

Offline Paddy

  • LandzDown Team
  • Hero Member
  • *****
  • Posts: 1376
Re: Great...I have a virus. Please help.
« Reply #11 on: July 13, 2009, 11:24:43 PM »
Make sure you update Malwarebytes >> the newest version 1.39 just released.
Don't be surprised if it askes you to reboot the computer after the update it did on this desktop,
tho it didn't on the laptop top or the other desktop..

Paddy.. :)
This is one race of people for whom psychoanalysis is of no use whatsoever - Sigmund Freud (about the Irish)

Never argue with a fool, they will lower you to their level and then beat you with experience.

Offline Aaron Hulett [MSFT]

  • Web Server Manager
  • Administrator
  • Hero Member
  • *****
  • Posts: 1098
  • I take the bus!
    • Microsoft Corporation
Re: Great...I have a virus. Please help.
« Reply #12 on: July 14, 2009, 12:13:33 AM »
Oh, and I only kept some important emails and old documents. 

No music, programs, vids, or anything downloaded.

"emails and old documents" fall within the scope of anything in the sentence, "Once the machine is infected, anything pulled off of it at that point is suspect."

The only potentially trustworthy backups from an infected system are those taken before the infection occurred.  After that, anything and everything on the system is potentially infected.  Everything.

//A
Aaron Hulett | Malware Protection Center | Microsoft Corporation
This post is provided "AS IS" without warranty, and confers no rights.

Offline woody189

  • Newbie
  • *
  • Posts: 22
Re: Great...I have a virus. Please help.
« Reply #13 on: July 14, 2009, 12:49:07 AM »

"emails and old documents" fall within the scope of anything in the sentence,

//A

Wow.. Sorry, I'm not exactly computer savvy, hence the thread.

I understand it's possible (then again, what isn't), but I don't think that's where it came from.

Everything was fine, and I recently downloaded a file, and then started to have problems.  When I ran the virus scan, the file I d/led was one of the files that came up as being infected.  It was then supposedly fixed, but I'm still having the problems.

Paddy, after I completed the scan, I realized that I didn't update.  I updated, rebooted, and reran the scan and still nothing came up as being infected.  Thanks for the idea though.

Offline Corrine

  • The Mystical Rose
  • Administrator
  • Hero Member
  • *****
  • Posts: 11540
  • "Stronger than the past, united in our goal."
    • Security Garden
Re: Great...I have a virus. Please help.
« Reply #14 on: July 14, 2009, 02:14:02 PM »
Let's take a look at what is on the computer. 
  • Download random's system information tool (RSIT) by random/random from here and save it to your desktop.
  • Double click on RSIT.exe to run RSIT.
  • Click Continue at the disclaimer screen.
  • Once it has finished, two logs will open. Please post the contents of both log.txt (<<will be maximized) and info.txt (<<will be minimized)
,  

Take a walk through the "Security Garden" -- Where Everything is Coming up Roses!

Remember - A day without laughter is a day wasted.
May the wind sing to you and the sun rise in your heart.