BleepingComputer.com: Infected... need some help.

Jump to content

Forum Rules

When posting your problem, do not run and post a ComboFix log. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.

To receive help, you should instead provide a detailed description of your problem, detailed word-for-word error messages that you are receiving, screenshots of strange behaviour, and your operating system. This information is much more useful to our helpers than a ComboFix log.


If you have not received help after three days, please post a link to your topic HERE.
Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Infected... need some help.

#1 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 01:43 PM

Hey guys, unfortunately I have somehow been infected by several high level security threats. I ran Avast yesterday and it said it found several viruses.

FirstScan

After trying to remove them, Avast scheduled a boot time scan for me, which I did. Here are the results:

BootTimeScan

As you can see more infected files were detected, but Avast was able to successfully move them all to the chest. However, after, when windows booted back up again, I was unable to open and run most programs. I assume this is because Avast removed important windows files to the chest, thus causing windows 7 problems like not being able to run most programs.
So, I did a system restore and everything went back to normal. I then ran a scan again with the following results.

AfterRestore

So, now I'm scared to take any further action because since these might be important windows files, removing them can cause problems, right? Which is what happened to me in my first attempt... I think.
I need some help removing these viruses guys, how do you remove something that's in these files? I ran both Malwarebytes and Ad-Aware, neither of them detected anything. What should I do now?
I really appreciate any help.

#2 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,388
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 24 September 2011 - 01:54 PM

In the images, can you please show the full path by expanding the column title called File Name?

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#3 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 02:05 PM

View Postcryptodan, on 24 September 2011 - 01:54 PM, said:

In the images, can you please show the full path by expanding the column title called File Name?


I don't think Avast has a feature that expands it. Only mousing over them each individually shows their full path. Give me a second please.

#4 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,388
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 24 September 2011 - 02:10 PM

See the line to the left of the S in the following:

Posted Image

Mouse over that and move it.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#5 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 02:26 PM

View Postcryptodan, on 24 September 2011 - 02:10 PM, said:

See the line to the left of the S in the following:

Posted Image

Mouse over that and move it.


Okay, I feel stupid now... thanks, haha.



Grrr... still not full, getting some better ones, will update shortly.

This post has been edited by SirToasty: 24 September 2011 - 02:38 PM


#6 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,388
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 24 September 2011 - 02:30 PM

Lets try a free scan with ESET online Scanner.

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#7 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 02:37 PM


#8 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 05:59 PM

View Postcryptodan, on 24 September 2011 - 02:30 PM, said:

Lets try a free scan with ESET online Scanner.



ESET found no threats.

#9 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,388
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 24 September 2011 - 09:26 PM

I think it would be safe to assume that the threats that Avast detected are false positives.;

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

#10 User is offline   SirToasty 

  • New Member
  • Pip
  • Find Topics
  • Group: Members
  • Posts: 6
  • Joined: 24-September 11

Posted 24 September 2011 - 09:41 PM

Really, so, should I ignore them? Or perhaps download AVG or AVIRA to double check?

#11 User is offline   cryptodan 

  • Bleepin Madman
  • PipPipPipPipPipPip
  • Find Topics
  • Group: BC Advisor
  • Posts: 18,388
  • Joined: 08-September 08
  • Gender:Male
  • Location:Catonsville, Md

Posted 25 September 2011 - 01:07 AM

I would ignore them, and also update your Java via http://www.java.com

My work schedule is as follows: Mon and Tues 1800 to 0600, Friday - Sunday 1800EST to 0600, and Wednesday to Thursday 1800est to 0600. So if I do not respond right away I am at work.
----------------
If I am helping you, then Please Send Me a Message!with your thread link in it. This is only if I haven't replied back to you within 24 to 48 hours.
----------------
My Main Site || My Backup Site || steam://friends/add/cryptodan Add me to your Steam Friends.

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users