Avast WEBforum

Other => Viruses and worms => Topic started by: fireinthesky on August 24, 2010, 06:22:41 PM

Title: Don't want to reformat Win32.Generic!BT , Win32:Bamital-X , and VBS.ExeDropper-g
Post by: fireinthesky on August 24, 2010, 06:22:41 PM
Hi i have a gateway 310s. It was infected with Win32.Generic!BT , Win32:Bamital-X , and VBS.ExeDropper-gen[Trj].

I have tried various software products to remove these files etc including spyware terminator, AVG, Avast etc.

I have tried safe mode that worked for a while but now doesn't . I've tried using chkdsk /p /r, fixmbr.

I would like to access the affected hard drives (2) to recover files before reformatting.

I'm thinking of putting the afflicted drives into another pc one at a time to get at the files I want to save. Is this possible without infecting another pc?

I'm open to ideas (aside from burning it in the yard or buying a mac)
Paul :(
Title: Re: Don't want to reformat Win32.Generic!BT , Win32:Bamital-X , and VBS.ExeDropper-g
Post by: CharleyO on August 24, 2010, 06:47:59 PM
***

Welcome to the forums, fireinthesky   :)

Try malwarebytes antimalware free version.

Download it, install it, update it, and then run a quick scan.

Post the results. You can get MBAM at the link below.

http://www.malwarebytes.org/mbam.php


***
Title: Re: Don't want to reformat Win32.Generic!BT , Win32:Bamital-X , and VBS.ExeDropper-g
Post by: Glitch on August 27, 2010, 03:14:15 AM
"I'm thinking of putting the afflicted drives into another pc one at a time to get at the files I want to save. Is this possible without infecting another pc?"

Yes, but It depends.

If you are slaving the drives and not booting from them (Infected ones),
No harm can come of this unless you are running infected files on the computer you are moving em to that is clean.

What OS isn't bootable?
It wont boot at all?



Title: Re: Don't want to reformat Win32.Generic!BT , Win32:Bamital-X , and VBS.ExeDropper-g
Post by: superhacker on August 27, 2010, 11:03:52 AM
Are you open to the idea of helping you ;),
Lets do it:
1.clear your temp files:http://www.piriform.com/ccleaner (http://www.piriform.com/ccleaner)
2.do a dr.web cure it scan:http://www.freedrweb.com/cureit/?lng=en (http://www.freedrweb.com/cureit/?lng=en)
3.scan with mbam:http://www.malwarebytes.org/mbam.php (http://www.malwarebytes.org/mbam.php)
4.post a Hijack Hunter log in this topic:http://www.novirusthanks.org/products/hijack-hunter/ (http://www.novirusthanks.org/products/hijack-hunter/)
5.we will provide a cleaning script,you should run it with Threat Killer