BleepingComputer.com: Infected with Cloud Protection virus

Jump to content

Forum Guidelines

Posted Image Read the following topic before creating a new topic in this forum. It contains instructions on the what we would like you to post, which will enable us to help you more quickly.

Preparation Guide For Use Before Using Malware Removal Tools and Requesting Help


Posted Image Unfortunately, with the amount of logs we receive per day, the average response time is 5 days. I want to assure you, though, that your topic will be looked at and responded to. So please be patient.


Posted Image DO NOT RUN ComboFix unless requested to.


Posted Image Only members of the Malware Response Team or Moderators are allowed to help people with logs. Anyone else should refrain from posting to another user's log.


Posted Image When posting a log please put the type of infection you have in the topic title. IE: Winfixer, Virtumonde, WinTools, WebSearch, Home Search Assistant, etc.


Posted Image Do not bump your topic. We try to resolve logs on a first come/first served basis. By bumping your log you will be pushed back in line due to the new date of your bump.
  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

Infected with Cloud Protection virus Tried self help to no avail--thanks for helping!

#31 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 01 November 2011 - 05:48 PM

I can't figure out how. There is no provision to save the file. I can highlight it, but it won't copy(I right click and nothing happens) Suggestions?

#32 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 02 November 2011 - 08:41 AM

Run OTL - Double-click OTL.exe Posted Image to start it.

  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :OTL
    @Alternate Data Stream - 784 bytes -> C:\WINDOWS\3203397148:3809022017.exe
    


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.


===

Please run download and run the ComboFix tool as suggested in post No. 2.
Post the log if you can.

Include the log from the OTL script.

#33 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 07 November 2011 - 07:43 AM

I tried to run OTL but it didn't do anything. Now it says it cannot access it. "You may not have the appropriate permissions to access the item"

Still can't repair the network connection for internet access. It can't renew the IP address.

#34 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 07 November 2011 - 10:14 AM

>>> Download Windows Repair: Please go here and click the "- Direct Download" to download tweaking.com_windows_repair_aio_setup.zip and save it to your Desktop. Then right-click on the new file => "Extract here".
Please open the new created folder "Tweaking.com - Windows Repair" and double-click "Repair_Windows.exe" (for Vista/W7, right-click on it =>"Run as administrator").

Start Repairs Options: Click the "Start Repairs" tab

Select Custom Mode.

If prompted to create a Restore point please do.

In the new window that opens click the "Unselect all" button to remove all the check-marks.
Then, please check the following and click the "Next" button.

* Reset Registry Permissions
* Reset File Permissions
* Repair Winsock & DNS Cache


---------

Check th Box "Restart System When Finished"

Click the Start Button.

Wait for the computer to restart.

Can you run the tools now?

How is the internet connection?

#35 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 08 November 2011 - 08:36 AM

No change---

While tweaking was running it showed an error that remote enabling(something like that) had a problem and needed to close. It was still running so I let it finish. There were 30 of those error messages.

#36 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 08 November 2011 - 09:16 AM

Run the Repair_Windows.exe recently downloaded and execute this.

System File Check utility: Click the "Step3"

>>> System File Check utility: Click the "Step3" tab and click the "Do it" button" under "System File Check".
Please follow the on-screen prompts. It can take a while to complete, so please be patient and restart your computer when it's done.

#37 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 09 November 2011 - 07:47 AM

Still no change.

#38 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 09 November 2011 - 10:00 AM

The difficulties with this computer are not tied to some immediate malware.

I suggest your create a new topic in the XP forum and explain your present difficulties with this computer.

http://www.bleepingcomputer.com/forums/forum56.html

I will keep this topic open for 5 days.

Please keep me posted.

#39 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 10 November 2011 - 12:02 PM

Are you saying that we've gotten rid of the rootkit virus and the remaining problems are unrelated?

Also, do you think my documents are safe to move to another computer?

Thanks for all your help!

#40 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 11 November 2011 - 08:12 AM

I can see nothing associated with malware.
Your documents should be ok.

The problem with your Internet connection can possibly be solved. If not then you will have to reinstall Internet Explorer or the operating system.

I have used all of the tools at my disposition to try to restore it.

#41 User is offline   ktms4me 

  • Member
  • PipPip
  • Find Topics
  • Group: Members
  • Posts: 30
  • Joined: 15-October 11

Posted 14 November 2011 - 09:43 AM

Thanks for all your help.

I suppose the other forum can handle the other continuing issues.

#42 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 14 November 2011 - 09:57 AM

You may want to try Microsoft fix.
http://support.microsoft.com/?kbid=811259

Make sure you do the instructions for the version of Windows XP SP1 or SP2 that is installed.

If that fails then try the other XP forum.

===

On my end:

Time for some housekeeping
    The following will implement some cleanup procedures as well as reset System Restore points:

    Click Start > Run and copy/paste the following bold text into the Run box and click OK:

    ComboFix /Uninstall

===

Delete the other tools we used.

Surf Safely, and Think Prevention!
===

#43 User is online   nasdaq 

  • Forum Addict
  • PipPipPipPipPipPip
  • Find Topics
  • Group: Malware Response Team
  • Posts: 5,053
  • Joined: 16-June 06
  • Gender:Male
  • Location:Montreal, QC. Canada

Posted 19 November 2011 - 11:09 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.

Share this topic:


  • 3 Pages +
  • 1
  • 2
  • 3
  • You cannot start a new topic
  • This topic is locked

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users