Author Topic: Win32:MBRoot-J  (Read 10596 times)

0 Members and 1 Guest are viewing this topic.

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #15 on: September 14, 2011, 02:27:05 PM »
i mean move to chest,
i havnt restored yet

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #16 on: September 14, 2011, 07:39:49 PM »
What are your current problems ?

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #17 on: September 14, 2011, 07:58:21 PM »
there still is a trojan on my computer, (so the Fcleaner says)
1 have done a payment with ing online banking and my tan has been blocked, because they had found a virus in my computer. then i tried to clean my computer, but still it says it has the virus in my computer and it is not easy to clear it with another program.

so can cannot pay anymore with ing online banking.

my computer seems to work normaly, though it is slow sometimes. i do not know right now if the virus (trojan) is my computer for bad intentions.


Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #18 on: September 14, 2011, 08:03:28 PM »
What virus does Fcleaner detect and what is its location ?

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #19 on: September 14, 2011, 08:06:44 PM »
This says the Fcleaner

------------------------------------------------------------------------------------------------------------------------
[13-09-2011 13:37:59] FCleaner v1.5.0.0 Loading...
[13-09-2011 13:38:00] Mebroot Infection Found!
[13-09-2011 13:38:00] FCleaner has detected malware on your system!
[13-09-2011 13:38:00] Please press the "Clean" button to remove the malware

it does not give an location, and if i want to clean it, it says that i have a big problem, and need assistance, because FCleaner, cant clean it...

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #20 on: September 14, 2011, 08:35:48 PM »
There was no indication of mebroot on your logs

But for peace of mind  ;D

Please read carefully and follow these steps.

  • DownloadTDSSKiller and save it to your Desktop.
  • Extract its contents to your desktop.
  • Once extracted, open the TDSSKiller folder and doubleclick on TDSSKiller.exe to run the application, then on Start Scan.



  • If an infected file is detected, the default action will be Cure, click on Continue.




  • If a suspicious file is detected, the default action will be Skip, click on Continue.




  • It may ask you to reboot the computer to complete the process. Click on Reboot Now.




  • If no reboot is require, click on Report. A log file should appear. Please copy and paste the contents of that file here.
  • If a reboot is required, the report can also be found in your root directory, (usually C:\ folder) in the form of "TDSSKiller.[Version]_[Date]_[Time]_log.txt". Please copy and paste the contents of that file here.

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #21 on: September 14, 2011, 08:45:55 PM »
okay thank you, i wil do it tomorrow at the "infected" computer and let you know.

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #22 on: September 14, 2011, 08:49:47 PM »
No problem, although as I say the original infection appears to have been removed by Combofix 

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #23 on: September 15, 2011, 10:55:33 AM »
I have runned the task killer (see results in the attached files)
then i runned avast (full scan and start up scan)
Result: no viruses found!

runned the fcleaner again, but still finds something
------------------------------------------------------------------------------------------------------------------------
[15-09-2011 10:42:30] FCleaner v1.5.0.0 Loading...
[15-09-2011 10:42:30] Mebroot Infection Found!
[15-09-2011 10:42:30] FCleaner has detected malware on your system!
[15-09-2011 10:42:30] Please press the "Clean" button to remove the malware
[15-09-2011 10:43:08] Cleaner finished! ...

(see attached file)

i think my computer is clean now, and fcleaner is wrong! ???

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #24 on: September 15, 2011, 07:30:14 PM »
Run TDSSKiller again please and could you post the log

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #25 on: September 16, 2011, 09:29:00 AM »
see attached file

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #26 on: September 16, 2011, 09:33:42 AM »
again (ANSI) instead of Unicode

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #27 on: September 16, 2011, 06:00:15 PM »
Methinks Fcleaner is providing a false positive, how is the computer behaving anything weird or unusual ?

seahorses

  • Guest
Re: Win32:MBRoot-J
« Reply #28 on: September 19, 2011, 07:35:31 AM »
no computer seems to work normally

Offline essexboy

  • Malware removal instructor
  • Avast Überevangelist
  • Probably Bot
  • *****
  • Posts: 40589
  • Dragons by Sasha
    • Malware fixes
Re: Win32:MBRoot-J
« Reply #29 on: September 19, 2011, 08:27:24 PM »
Try an update on the Fcleaner and then re-run it