Avast WEBforum

Consumer Products => Avast Free Antivirus / Premium Security (legacy Pro Antivirus, Internet Security, Premier) => Topic started by: BARRIOSWJ on April 19, 2013, 01:44:46 AM

Title: FBI Virus Removal
Post by: BARRIOSWJ on April 19, 2013, 01:44:46 AM
Hello, I posted all my reports to help me with the virus removal this morning under Avast support Forums for Business protection and still haven't received a response from anyone. Can anyone help me with it? I can repost the reports here if needed.
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 19, 2013, 01:46:24 AM
Here are the rest of the reports
Title: Re: FBI Virus Removal
Post by: Pondus on April 19, 2013, 02:00:32 AM
virus problems should be posted in the forum section where you found the guide. .... virus and worms.   ;)

anyway done is done

malware removers are notified, check back late tomorrow as they are all in bed now


OBS... it seems you have avast and McAfee installed?

Title: Re: FBI Virus Removal
Post by: essexboy on April 19, 2013, 01:51:40 PM
Hi what are the problems you are experiencing .. As it stands I can see no sign of the ransom malware

Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 19, 2013, 06:19:29 PM
If i try and open an application it wants me to select the application to use for opening the application. MBAM keeps popping up stating that it blocked a potentially unsafe ip address. So you think all the programs I ran, removed whatever was remaining and fixed all my shortcuts?
Title: Re: FBI Virus Removal
Post by: essexboy on April 19, 2013, 07:35:45 PM
Are they applications exe files or are the document type files where you get the error ?

Generally MBAM has a bit of an overkill on IP addresses
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 19, 2013, 10:20:18 PM
they are exe applications. For example, I choose Internet Explorer or Avast Application, It open the windows box to "Open With"  and has me select a recommended application.
Title: Re: FBI Virus Removal
Post by: bob3160 on April 19, 2013, 10:41:36 PM
I think that BARRIOSWJ may have been a victim of the following:
http://www.theinquirer.net/inquirer/news/2262248/flawed-malwarebytes-security-update-wipes-out-thousands-of-computers (http://www.theinquirer.net/inquirer/news/2262248/flawed-malwarebytes-security-update-wipes-out-thousands-of-computers)


For a fix, look at the following:
http://forums.malwarebytes.org/index.php?showtopic=125136 (http://forums.malwarebytes.org/index.php?showtopic=125136)
Hope that helps.
Title: Re: FBI Virus Removal
Post by: essexboy on April 19, 2013, 11:45:27 PM
If Bob's fix does not work I will reset the associations for you
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 20, 2013, 12:53:21 AM
Bob's fix did not work. Now what?
Title: Re: FBI Virus Removal
Post by: bob3160 on April 20, 2013, 01:22:37 AM
If Bob's fix does not work I will reset the associations for you
It isn't my fix but one that Malwarebytes posted.
Title: Re: FBI Virus Removal
Post by: essexboy on April 20, 2013, 04:36:44 PM
OK there is a nice registry fix here which will reset all associations to default, http://www.sevenforums.com/tutorials/19449-default-file-type-associations-restore.html
Initially download and merge the exe file fix to your desktop
Double click the file and allow to merge, has that cured it ?
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 22, 2013, 07:37:18 PM
no...I'm still having issues. none of the merges worked on that fix. It seems though the computer is fixed from the virus but all these extensions are corrupt.
Title: Re: FBI Virus Removal
Post by: essexboy on April 22, 2013, 08:42:50 PM
Could you create another user and see if the problem persists there
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 22, 2013, 10:17:59 PM
It seems though it is just that user profile. New user was able to open everything.
Title: Re: FBI Virus Removal
Post by: bob3160 on April 22, 2013, 10:25:16 PM
Is the following of any help ???
http://support.microsoft.com/kb/950505 (http://support.microsoft.com/kb/950505)
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 22, 2013, 10:40:40 PM
I will test that out as soon as the Bootscan completes. Last log ran still shows Virus detected.
Title: Re: FBI Virus Removal
Post by: SpeedyPC on April 23, 2013, 02:58:27 PM
I'm not 100% sure about Hitman Pro Kickstart which has the tools to remove the FBI warning virus see link http://www.surfright.nl/en/hitmanpro/kickstart let essexboy make his decision about Hitman Pro Kickstart before you go any further to you're PC.
Title: Re: FBI Virus Removal
Post by: essexboy on April 23, 2013, 04:20:04 PM
Could you let me know what programme is detecting this and the location of the file
Title: Re: FBI Virus Removal
Post by: BARRIOSWJ on April 23, 2013, 07:56:58 PM
just ran the bootscan twice and no virus was found.. However any exe files (ie Avast or Excel) to open apps must now be opened either as Runas Admin or select application from list of recommended applications. tried above recommendations but nothing seems to work. Everything seems to be workign fine on the new user profile.
Title: Re: FBI Virus Removal
Post by: essexboy on April 23, 2013, 08:33:26 PM
Are you able to transfer everything over to the new profile ?  As the main one appears to be corrupted