xfrankyx Posted May 31, 2009 Report Share Posted May 31, 2009 Hey guys,Hope all is well :). I think I got a serious virus on one of my office computer and I would real appreciate if someone can help me out. I own a web design company and one of my computer caught something really nasty. Its caused a lot of down time and now a days, that's not good for business at all. Time equals money and you know how that goes. I cant afford the time for a total format at this time so I'm hoping this could be worked out.So here are some specs...Dell Dimension 4700Windows XP service pack 3These are the events that led to this (prior to this, no issues on the pc)...One of my designers got a Microsoft validation pop up and when ahead and did it, after that, the major issues started. I guess that was the cause but Ive seen one of those and they don't look suspicious at all. Ive done it on one of my other pcs and haven't noticed any issues with that PC at all. Either way, major screw up on our end. Right after that, things started going crazy. Computer freezes, programs freeze, programs shuts down, the usual. Next a bunch of windows pop ups keep coming up, Ive taking screen caps of those, posted below. So we got a free version of avg to see if something serious and avg showed we did have a Trojan installed.So right after that, I get Bit Defender, full version. installed and do a scan right away. Whats weird is that Bit Defender does pick up anything and tells me everything is fine. But after that, I get the same regular pops up before I installed bit defender and also, every few hours, bit defender is telling me its blocked off a few viruses and either deletes them or puts them in quarantine.Here are the images below....Can someone please help me out and let me know what I got to do to take this virus off my pc. There is still obviously a issue seems like.Let me know if you guys needs anymore info from me.Thanks much in advanceappreciate it. Quote Link to comment Share on other sites More sharing options...
Boris Posted May 31, 2009 Report Share Posted May 31, 2009 Download and install Malwarebytes Anti-Malwarehttp://www.malwarebytes.org/mbam.phpUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Let it quarantine/kill whatever it findsThem download and install Spybot - Search & Destroy 1.6.2http://www.safer-networking.org/en/download/index.htmlUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Follow the instructions at the end of the scan.Post back on the results after you have done this. Quote Link to comment Share on other sites More sharing options...
Belatucadrus Posted May 31, 2009 Report Share Posted May 31, 2009 A few questions:-1) Did AVG delete the Trojan it found ?2) Did you uninstall AVG before installing BitDefender ? having two antvirus on the same PC is a recipe for disaster.3) Were you aware that the license terms for the free versions are for non profit home use, another good reason to remove it. Quote Link to comment Share on other sites More sharing options...
-pops- Posted May 31, 2009 Report Share Posted May 31, 2009 It is unwise to run any computer without a backup. It is complete folly to run a business computer without a properly formalised backup system and procedure.When you are up and running again, give this matter your urgent attention. It will avoid lots of high blood pressure and possible despair Quote Link to comment Share on other sites More sharing options...
xfrankyx Posted June 3, 2009 Author Report Share Posted June 3, 2009 Sorry it took so long to reply, but I was dealing with a tragic emergency. I come with bad news. I'm sorry to announce that at 11:30, Monday the 1st of the month of June, my hard drive crashed.Was working fine for a few hours in the morning and then it just died. Restarting brought along the "NTLDR is missing" error. So I put it as a slave on my other computer and backed up all the data from the crashed hard drive. I'm assuming the viri just ate up the OS beause it was reading fine as a slave on another computer. After something like that, I didn't even want to take the risk and I got a new HD, installed a fresh windows and basically just rebuilt my system again from ground up, minus any of the older data from the crashed HD, which might have contained viri.What i wanted to confirm is that none of the old data I'm bringing back on my new HD has been infected and will end up infecting my new OS.And whats extremely weird is that during the rebuilding process, i got two pop ups which made me feel as if I was already infected, these are the images of those below...I'm not even sure what this is but I don't see how this can pop up only after a hour of me installing a fresh os.This is the original Windows pop up that got me infected the first time.Do you guys agree this was Malware or the cause of the virus or is this something clean and the virus came from somewhere else. Because like said, right after I did this Windows Genuine is when my pc went haywire. Either way do you guys think its best if I put the old HD as a slave to the new HD, and run all these steps?Download and install Malwarebytes Anti-Malwarehttp://www.malwarebytes.org/mbam.phpUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Let it quarantine/kill whatever it findsThem download and install Spybot - Search & Destroy 1.6.2http://www.safer-networking.org/en/download/index.htmlUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Follow the instructions at the end of the scan.Post back on the results after you have done this.Should I still run this and make sure I get the slave as a part of the scan?"A few questions:-1) Did AVG delete the Trojan it found ?2) Did you uninstall AVG before installing BitDefender ? having two antvirus on the same PC is a recipe for disaster.3) Were you aware that the license terms for the free versions are for non profit home use, another good reason to remove it.1) No it only found it, it was a free version so their upsale is that you have to buy AVG to take the trojan out. I went with BitDefender though, because reviews say its top in its class. 2) yes I did3) yup got rid of that. It is unwise to run any computer without a backup.It is complete folly to run a business computer without a properly formalised backup system and procedure.When you are up and running again, give this matter your urgent attention. It will avoid lots of high blood pressure and possible despairYour right. Learned the hard way. I just got acronis image program and backed up my system. Can you recommend a better one. or maybe a better system. I'm very new to the field of having automated backups made on my business computers. Thanks much guysApprecaite the help Quote Link to comment Share on other sites More sharing options...
Dencandy Posted June 3, 2009 Report Share Posted June 3, 2009 The Windows Genuine Advantage pop-up looks genuine. You can check by installing IE7 or 8 and clicking on on the "What is WGA.." and using the phishing filter to check the site. However, you do not need to install that WGA module & some people claim it causes problems. The main thing you have to do after re-installing Windows is to re-activate it.The other pop-up from Registry Update is part of a rogue registry fix scam which Malwarebytes should be able to remove (it must have come from one of your data or utility files). I also recommend you scan with a free on-line scanner such as the highly regarded ESET/NOD32 SCANNER. After that update Windows asap.Windows Messenger is well-known for security flaws & if you don't use it it's best uninstalled. There's also something called Windows Mesenger Service which allows pop-ups and can be disabled. Read about how to deal with both AT THIS LINK from PCHell.Also follow the advice given by others above.We all live and learn the hard way with Windows! B) Quote Link to comment Share on other sites More sharing options...
Belatucadrus Posted June 3, 2009 Report Share Posted June 3, 2009 1) No it only found it, it was a free version so their upsale is that you have to buy AVG to take the trojan out.This is a odd as the free version of AVG doesn't normally have any such limitations, where did you get it from ? My concern is caused by some dubious people hanging their naff products on Google searches for reputable products. Quote Link to comment Share on other sites More sharing options...
Hb_Kai Posted June 4, 2009 Report Share Posted June 4, 2009 In AVG is proving its uselesness, there's always TrendMicro?About the Windows Messenger flaws - what usually comes through Windows Live / Windows Messenger are Win32 viruses or worms. Most virus scanners find difficulty finding or actually removing these. Windows usually comes with its own Win32 scanner called MRT. This is really good for finding them worms. Quote Link to comment Share on other sites More sharing options...
xfrankyx Posted June 16, 2009 Author Report Share Posted June 16, 2009 HEY GUYS, HOPE ALL IS WELL. SORRY ABOUT THE DELAYED RESPONSE. I GOT SOME UPDATES AND I HOPE YOU GUYS CAN CHECK IT OUT AND LET ME KNOW WHAT YOU THINK. Download and install Malwarebytes Anti-Malwarehttp://www.malwarebytes.org/mbam.phpUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Let it quarantine/kill whatever it findsThem download and install Spybot - Search & Destroy 1.6.2http://www.safer-networking.org/en/download/index.htmlUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Follow the instructions at the end of the scan.Post back on the results after you have done this.ATTACHED IS THE MALWAR RESULTS. THE SPYBOT PROGRAM, I DONT RECALL IT HAD A OPTION TO SAVE THE RESULTS. IT DID FIND A FEW THINGS WHICH I DELETED JUST LIKE IN MALWAR. LET ME KNOW WHAT YOU THINK. THANKSThe Windows Genuine Advantage pop-up looks genuine. You can check by installing IE7 or 8 and clicking on on the "What is WGA.." and using the phishing filter to check the site. However, you do not need to install that WGA module & some people claim it causes problems. The main thing you have to do after re-installing Windows is to re-activate it.The other pop-up from Registry Update is part of a rogue registry fix scam which Malwarebytes should be able to remove (it must have come from one of your data or utility files). I also recommend you scan with a free on-line scanner such as the highly regarded ESET/NOD32 SCANNER. After that update Windows asap.Windows Messenger is well-known for security flaws & if you don't use it it's best uninstalled. There's also something called Windows Mesenger Service which allows pop-ups and can be disabled. Read about how to deal with both AT THIS LINK from PCHell.Also follow the advice given by others above.We all live and learn the hard way with Windows!YEAH IM GOING TO LEAVE THAT WGA ALONE BECAUSE THIS ISSUE STARTED RIGHT AFTER THAT. I ALREADY ACTIVATED WINDOWS SO GOOD ON THAT AND DISABLED THE OTHER WINDOWS MESSENGER POPUPS. I RAN THE "ESET/NOD32" SCANNER AND IT DID NOT FIND ANYTHING. This is a odd as the free version of AVG doesn't normally have any such limitations, where did you get it from ? My concern is caused by some dubious people hanging their naff products on Google searches for reputable products.I GOT IT FROM DOWNLOAD.COM I BELIEVE. In AVG is proving its uselesness, there's always TrendMicro?About the Windows Messenger flaws - what usually comes through Windows Live / Windows Messenger are Win32 viruses or worms. Most virus scanners find difficulty finding or actually removing these. Windows usually comes with its own Win32 scanner called MRT. This is really good for finding them worms.I RAN THE MRT SCAN, AND IT FOUND NOTHING EITHERSPEAKING OF TRENDMICRO, I ALSO RAN KASPERSKY SCANS AND THESE ARE THE RESULTS HERE...http://paperstreetmedia.com/kaspersky_results.txthttp://paperstreetmedia.com/kaspersky_results.html---------------------------------------------IF YOU CAN, PLEASE CHECK THOSE OUT AND LET ME KNOW WHAT YOU GUYS THINKTHANKSmbam_log_2009_06_03__22_54_20_.txt Quote Link to comment Share on other sites More sharing options...
ɹəuəllıʍ ʇɐb Posted June 16, 2009 Report Share Posted June 16, 2009 Please do not type ALL CAPS, as it is very difficult to read. Quote Link to comment Share on other sites More sharing options...
xfrankyx Posted June 17, 2009 Author Report Share Posted June 17, 2009 Please do not type ALL CAPS, as it is very difficult to read.Sorry about that. Noted for next time.Can someone please check out those results and let me know what you guys think. I would really appreciate it. Thanks Quote Link to comment Share on other sites More sharing options...
Boris Posted June 17, 2009 Report Share Posted June 17, 2009 HEY GUYS, HOPE ALL IS WELL. SORRY ABOUT THE DELAYED RESPONSE. I GOT SOME UPDATES AND I HOPE YOU GUYS CAN CHECK IT OUT AND LET ME KNOW WHAT YOU THINK. Download and install Malwarebytes Anti-Malwarehttp://www.malwarebytes.org/mbam.phpUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Let it quarantine/kill whatever it findsThem download and install Spybot - Search & Destroy 1.6.2http://www.safer-networking.org/en/download/index.htmlUpdate it and then reboot into Safe Mode (hold down F8 key while booting) and do a full scan.Follow the instructions at the end of the scan.Post back on the results after you have done this.ATTACHED IS THE MALWAR RESULTS. LET ME KNOW WHAT YOU THINK.MalwareBytes found a Trojan in your System Restore - did you let it remove the Trojan ? Quote Link to comment Share on other sites More sharing options...
xfrankyx Posted June 19, 2009 Author Report Share Posted June 19, 2009 MalwareBytes found a Trojan in your System Restore - did you let it remove the Trojan ?It says no action there but I did run it after and delete it. Quote Link to comment Share on other sites More sharing options...
madeinUSA Posted October 27, 2009 Report Share Posted October 27, 2009 Trojan Remover maybe will help you. Quote Link to comment Share on other sites More sharing options...
Recommended Posts
Join the conversation
You can post now and register later. If you have an account, sign in now to post with your account.