Author Topic: Virus I can't get rid of  (Read 7397 times)

0 Members and 1 Guest are viewing this topic.

dutoit

  • Guest
Virus I can't get rid of
« on: September 15, 2009, 07:07:59 PM »
Hi
Please help!

PLease excuse I'm new at this
.
-My Avast detects 2 files in the background scanner every time I connect to the internet.
-I can't delete, or repair the files and if I move or rename them they just come back.
-the files are named:  d1al.exe and  LoL_1_.jpg
-They are in temporary internet files folder
-It began yesterday and I have no clue as to how it got onto my system
-Avast gives me the following message: Win32:Trojan-gen {Other}

It disconnects me from the internet every time I connect to my wireless internet

Please help if you can

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #1 on: September 15, 2009, 07:09:45 PM »
can you some how upload the files(one at time) to virustotal.com and post the link.

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #2 on: September 15, 2009, 07:14:14 PM »

dutoit

  • Guest

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #4 on: September 15, 2009, 07:19:31 PM »
did you try avast! boot time scan?, no? : http://www.digitalred.com/avast-boot-time.php (move all the files infected to chest, when asked what to do)

post back.

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #5 on: September 15, 2009, 07:24:00 PM »
I didn't try the boot time scan will do so now

Every time I move it to the chest it reappears again and I'm prompted again, I did this a few times and it still comes back

prashant_sharma1984

  • Guest
Re: Virus I can't get rid of
« Reply #6 on: September 15, 2009, 07:31:12 PM »
Hello,


1. Try cleaning up the Temporary files folder.
2. Boot your PC In safe mode and networking .
3. Step 2 done then try downloading one of the following :
    a) Malware antibytes
    b) Super anti spyware
Update the database and do a full system scan..

Let me know if this was helpfull.

Regards,
Prashant Sharma


 




Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #7 on: September 15, 2009, 07:32:44 PM »
move to chest in the sense during boot time scan it asks what to do with the infected file. select move to chest.

edit : remove the temporary files after the boot time scan.
« Last Edit: September 15, 2009, 07:36:52 PM by nmb »

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #8 on: September 15, 2009, 08:20:37 PM »
Okay did the boot time scan and moved the files to the chest when propmted.
The result now produced more 3 more infected files in the system volume information folder with the names A0031464.exe, A00331496.exe, and A0031745.exe

I cleaned out the temporary internet files folder after the scan and rebooted

The problem persists,
will try and download the other 2 programs now

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #9 on: September 15, 2009, 08:31:44 PM »
yup, now you can try other two programs. do not worry about the adware cookies reported by superantispyware. let it deal it self.

get mbam here : malwarebytes.org update and perform full scan. post log here, please.

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #10 on: September 15, 2009, 09:21:18 PM »
I got the log and found 6 files infected

Should I remove them?

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 1
Registry Values Infected: 1
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{67kln5j0-4opm-01we-aax2-5657qca554112} (Backdoor.Bot) -> No action taken.

Registry Values Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ravav (Worm.RJump) -> No action taken.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\Start Page (Hijack.Homepage) -> Bad: (http://www.iesearch.com/) Good: (http://www.Google.com/) -> No action taken.

Folders Infected:
C:\VIDI\UNUK (Backdoor.Bot) -> No action taken.

Files Infected:
C:\VIDI\UNUK\DRG.exe (Backdoor.Bot) -> No action taken.
C:\VIDI\UNUK\DesKTop.ini (Backdoor.Bot) -> No action taken.
« Last Edit: September 15, 2009, 09:23:08 PM by dutoit »

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #11 on: September 15, 2009, 09:23:20 PM »
exit all the browsers you are using, remove the infections. and reboot if asked to do so.

was it a quick scan or full scan?.

come back.

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #12 on: September 15, 2009, 09:48:31 PM »
Hey,
It was a full scan.

 looks like it worked! All files were removed after the reboot and I haven't had a detection as yet

Thanks for everything you were really helpful!   ;)

Offline nmb

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3054
Re: Virus I can't get rid of
« Reply #13 on: September 15, 2009, 09:50:25 PM »
great that everything is fine now. consider this, please:

secunia psi : http://secunia.com/vulnerability_scanning/personal/

welcome to the forums.

dutoit

  • Guest
Re: Virus I can't get rid of
« Reply #14 on: September 15, 2009, 09:54:36 PM »
I will have a look,
thanks again