LandzDown Forum

Security => Analysis and Malware Removal => Topic started by: solopdle on June 05, 2011, 03:28:31 PM

Title: Virus has shut down all my protection options
Post by: solopdle on June 05, 2011, 03:28:31 PM
I was referred to your website by searching through some other websites, Corrine was mentioned. My computer prompted me to run an update and I guess I wasnt paying attention and let a virus (malware) something very nasty in. I tried to run my AVG scan in safe mode but the virus wont allow it. I went through your post for registry but the virus wont let me in to check if i am running in 32 or 64 bit. Non of my scanning software will work and I managed an internet connection but it took awhile to figure it out and now I assume am running uprotected. Any help is appreciated. 
Title: Re: Virus has shut down all my protection options
Post by: Corrine on June 05, 2011, 03:38:04 PM
Hi, solopdle.  Welcome to LandzDown Forum.

We will do our best to assist you.  However, in order to do so, please follow all instructions provided in the sequence given.  Do not install/re-install any programs or run any fixes or scanners that you have not been instructed to use.  This may cause conflicts with the tools being used in the cleanup process.   

If you have questions regarding any of the instructions or problems running any tools, please let us know.

It would be helpful if you know the name of the fake/rogue that was installed.  However, in the meantime, let's see if this will work.
Please download rkill from one of the following links and save to your Desktop:

One (http://download.bleepingcomputer.com/grinler/rkill.exe), Two (http://download.bleepingcomputer.com/grinler/rkill.com),Three (http://download.bleepingcomputer.com/grinler/rkill.scr) or Four (http://download.bleepingcomputer.com/grinler/rkill.pif)
Notes:

If you you receive security warnings about rkill, please ignore and allow the download to continue.

Please download Malwarebytes' Anti-Malware (http://www.malwarebytes.org/mbam.php) to your desktop.

** Note **

If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts. Click OK to either and let MBAM proceed with the disinfection process. If asked to restart the computer, please do so immediately.

Please also provide the following two logs.  Note that you may need more than one reply to get all the information posted.

Download DDS.scr by sUBs from one of the following links and save it to your desktop.
Link 1 (http://download.bleepingcomputer.com/sUBs/dds.scr)
Link 2 (http://www.forospyware.com/sUBs/dds)