Author Topic: virus help  (Read 13836 times)

0 Members and 1 Guest are viewing this topic.

Alpha32

  • Guest
Re: virus help
« Reply #30 on: February 19, 2011, 07:10:10 PM »
I'm already in safe mode, been in it since 12pm (got fed up with the constant restarts caused by System Tools) - Safe Mode with Networking

argus

  • Guest
Re: virus help
« Reply #31 on: February 19, 2011, 08:06:20 PM »
Delete Combofix icon from the desktop.

Download the new Combofix to your desktop http://download.bleepingcomputer.com/sUBs/ComboFix.exe

 When you download the program to be completed,

Start >> Run
Code: [Select]
%UserProfile%\desktop
Enter


Rename the Combofix-in iexplore.exe.

Note,The display extension ComboFix.exe be called iexplore.exe(is wrong iexplore.exe.exe) .

Then run Combofix

Give me new log when you get one   

Alpha32

  • Guest
Re: virus help
« Reply #32 on: February 19, 2011, 08:13:14 PM »
Start >> Run
Code: [Select]
%UserProfile%\desktop
Enter   
Sorry about this i must be really annoying but if I do that it'll just bring up the desktop in a window won't it?

Rename the Combofix-in iexplore.exe.

Note,The display extension ComboFix.exe be called iexplore.exe(is wrong iexplore.exe.exe) . 
I also don't get that part :-[ (ain't been asleep yet, been wanting to get rid of the virus first, thats my excuse for the noob questions tho)

Edit: after doing that patch thing on secunia, it isn't coming up on normal no more and I can now run Malwarebytes in normal mode so I did a scan on mbam and it's found 1 infected object, however according to bleep computers it should find 4

but it isn't system tools, what it found was Spyware.Zbot

log:

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5812

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

19/02/2011 20:01:46
mbam-log-2011-02-19 (20-01-46).txt

Scan type: Quick scan
Objects scanned: 165851
Time elapsed: 3 minute(s), 34 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\Users\Admin\AppData\Local\Temp\jar_cache2978039640436424214.tmp (Spyware.Zbot) -> Quarantined and deleted successfully.


So the question is.. is it still on my system hiding (must be? wasn't removed) or am I missing something :-\ - currently doing a full scan with mbam, should I do a scan with avast aswell and see if that brings something up? Because I couldn't do one last time cos pc kept restarting every 35 minutes, which wasn't long enough to complete the scan

Full scan

Malwarebytes' Anti-Malware 1.50.1.1100
www.malwarebytes.org

Database version: 5812

Windows 6.0.6001 Service Pack 1
Internet Explorer 7.0.6001.18000

19/02/2011 21:35:53
mbam-log-2011-02-19 (21-35-53).txt

Scan type: Full scan (C:\|S:\|)
Objects scanned: 426566
Time elapsed: 1 hour(s), 18 minute(s), 9 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 0
Folders Infected: 0
Files Infected: 1

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
(No malicious items detected)

Registry Keys Infected:
(No malicious items detected)

Registry Values Infected:
(No malicious items detected)

Registry Data Items Infected:
(No malicious items detected)

Folders Infected:
(No malicious items detected)

Files Infected:
c:\programdata\bdamdbk09000\bdamdbk09000.exe (Spyware.Zbot) -> Quarantined and deleted successfully.

If they're in the quarantine does that mean they could still cause problems or is it like on avast where they can't be run and no damage can be done? Is it best to keep in there or delete permanently? or is both just as each other? Still love to know where System Tools is
« Last Edit: February 19, 2011, 11:10:29 PM by Alpha32 »

argus

  • Guest
Re: virus help
« Reply #33 on: February 20, 2011, 09:17:09 AM »
Try now run Combofix in normal mode.
Disable AV.

Quote
Is it best to keep in there or delete permanently?

irrelevant
« Last Edit: February 20, 2011, 09:23:13 AM by argus »

Offline Tarq57

  • Avast Evangelist
  • Massive Poster
  • ***
  • Posts: 3694
  • If at first you don’t succeed; call it version 1.0
Re: virus help
« Reply #34 on: February 20, 2011, 09:20:54 AM »
They're safe in the quarantine, unless you deliberately release them.
Windows 10,Windows Firewall,Firefox w/Adblock.

Alpha32

  • Guest
Re: virus help
« Reply #35 on: February 20, 2011, 05:41:23 PM »
Ok, did the scan and it seemed to run fine and made a log but have no idea what it all means haha ::)

argus

  • Guest
Re: virus help
« Reply #36 on: February 20, 2011, 08:10:24 PM »
The CF log seems clean and there is no traces of malware. Your PC is clean.

It is necessary to uninstall Combofix

Start >> Run

Combofix /Uninstall

Enter.

Alpha32

  • Guest
Re: virus help
« Reply #37 on: February 20, 2011, 08:22:35 PM »
Where did the fake anti virus (System Tools) go to? because it wasn't removed or did patching Java fix it?

Thanks for all your help!