Author Topic: Possible multiply infections including cool.vbs virus  (Read 2294 times)

0 Members and 1 Guest are viewing this topic.

Ricky Vybz

  • Guest
Possible multiply infections including cool.vbs virus
« on: November 06, 2013, 09:25:52 PM »
Hello everyone,

I have a system that has been exposed to an infected flash drive that had infected another computer with the cool.vbs virus. With the help of magna86 and other members on this forum I was able to neutralize the cool.vbs virus along with other issues on that system and also clean/fix the infected flash drive :).

Now this system I currently looking into was exposed to the same infected flash drive and unfortunately there was no anti-virus software installed on the system, hence I am not sure whether or not it got infected, also since it had no anti-virus software installed I am assuming there could be many other viruses hanging out on it. I have not had any adverse issues with the system, everything runs okay but to be on the safe side I want to ensure that it is clean after which I will install a version of Avast on it. The system is running Windows 7 Ultimate (32 bit). I have attached the various logs and I ask for your help in identifying any viruses that are on the system and help me to remove them.

I look forward to the expert advice and knowledge of members of this forum.

Thanks in advance,

Ricky. 

Ricky Vybz

  • Guest
Re: Possible multiply infections including cool.vbs virus
« Reply #1 on: November 06, 2013, 09:27:58 PM »
More logs...

Offline Pondus

  • Probably Bot
  • ****
  • Posts: 37550
  • Not a avast user
Re: Possible multiply infections including cool.vbs virus
« Reply #2 on: November 06, 2013, 09:35:40 PM »
removal guys are notified.    ;)


you may run AdwCleaner again... and click clean




Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible multiply infections including cool.vbs virus
« Reply #3 on: November 06, 2013, 09:42:05 PM »
Looks like MCShield and MBAM between them got it

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following


Code: [Select]
:Commands
[CREATERESTOREPOINT]

:OTL
[2013/09/18 05:49:46 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions\ffxtlbr@babylon.com
O2 - BHO: (Babylon toolbar helper) - {2EECD738-5844-4a99-B4B6-146BF802613B} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.6.9.12\bh\BabylonToolbar.dll (Babylon BHO)
O3 - HKLM\..\Toolbar: (Babylon Toolbar) - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files\BabylonToolbar\BabylonToolbar\1.6.9.12\BabylonToolbarTlbr.dll (Babylon Ltd.)
O3 - HKU\S-1-5-21-3371199651-1158534765-2135718783-1000\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
[2012/09/04 15:37:07 | 000,000,000 | ---D | M] -- C:\Users\SUPERUSER\AppData\Roaming\BabylonToolbar

:Commands
[resethosts]
[emptytemp]
[Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

Ricky Vybz

  • Guest
Re: Possible multiply infections including cool.vbs virus
« Reply #4 on: November 06, 2013, 11:13:59 PM »
Thanks for the speedy response, you guys are awesome  8)

The OTL scan is attached as OTL2.txt, after the Run/Fix was done a log report was produced, I also attached that log.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible multiply infections including cool.vbs virus
« Reply #5 on: November 06, 2013, 11:20:42 PM »
How is the computer running .. Any problems ?

Ricky Vybz

  • Guest
Re: Possible multiply infections including cool.vbs virus
« Reply #6 on: November 06, 2013, 11:46:58 PM »
I am not having any problems with the computer, as I said earlier everything was running okay but I just wanted to make sure it was clean since I know that a known infected flash drive was plugged into the system. It boots up faster now and I am not having any problems at all.

Does the logs show that the system is clean now? Thanks much.

Ricky

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Possible multiply infections including cool.vbs virus
« Reply #7 on: November 07, 2013, 02:56:11 PM »
Yes the system looks clean, all I had left to remove was some adware

Run OTL and press the cleanup button to remove it :)