Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

I AM infected, but can't seem to remove it


  • Please log in to reply
3 replies to this topic

#1 Youga

Youga

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:15 PM

Posted 06 June 2009 - 08:39 AM

I'm trying to remove a virus from a laptop. It runs Windows XP. When I first received the pc to fix it, it had quite a few symptoms. The background was changed, antivirus 2009 (or something like that) was installed, no programs would run, web traffic was rerouted to the local host, popups would come, taskmanager and regedit were disabled. After running, malwarebytes' Anti-Malware, 3 items kept appearing. Two items were trackers, and one item was the waledac trojan. I then ran combofix I thought I had removed everything. However, the combofix log still listed userinit as infected and as soon as the computer got internet connection again, the viruses/spyware started to come back. I then ran bitdefender 2009 and it removed a few more items. It really seemed it was clear at the time, but just to be safe I went ahead and removed bitdefender and was putting on avast antivirus as a free antivirus scanner to hopefully prevent this from happening in the future for the user. While avast was scanning, it detected 3 malware (all 3 were .dlls it couldn't delete) and told me that there was a virus infecting system memory, to restart, and do a boot time scan. I did the boot time scan, it found 1 item, deleted it, and then started up but it keeps finding the .dlls, can't delete them, and tells me there is a virus in the memory (which it can't seem to remove). I'm in the process of finishing up running Microsfoft Windows Malicious Software Removal Tool, but it hasn't found anything yet and is about 97% done.

Any suggestions?

BC AdBot (Login to Remove)

 


#2 snowdrop

snowdrop

  • Members
  • 513 posts
  • OFFLINE
  •  
  • Local time:05:15 PM

Posted 06 June 2009 - 08:58 AM

Welcom to this forum :flowers:

A suggestion to help you is for you to fully update the Malwarebytes program, reboot the computer and run a quick scan with it; then post the report from that scan for someone to check for you ...

To advise you about the ComboFix tool .......Please do note the message in Blue at the top of this section of this forum

When posting your problem, do not run and post a ComboFix logs. ComboFix is a tool that should only be run under the supervision of someone who has been trained in its use. Using it on your own can cause problems with your computer. Any posts containing CF Logs will be ignored.


Lets see the report from the Malwarebytes scan and get someone to check it for you and go from there :thumbsup:

#3 Youga

Youga
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:15 PM

Posted 06 June 2009 - 10:28 AM

Mbam log

Malewarebytes' Anti-Malware 1.37
Database version: 2236
Widnows 5.1.2600 Service Pack 2

6/6/2009 11:23:20 AM
mbam-log-2009-06-06 (11-23-20).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 220902
Time elapsed: 1 hour(s), 15 minute(s), 40 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious Items detected)

Memory Modules Infected:
(No malicious Items detected)

Registry Keys Infected:
(No malicious Items detected)

Registry Values Infected:
(No malicious Items detected)

Registry Data Items Infected:
(No malicious Items detected)

Folders Infected:
(No malicious Items detected)

Files Infected:
C:\tj.vbs (Malware.Trace) -> Quarantined and deleted successfully

#4 Youga

Youga
  • Topic Starter

  • Members
  • 3 posts
  • OFFLINE
  •  
  • Local time:06:15 PM

Posted 06 June 2009 - 03:09 PM

I am still infected. What do I do now?




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users