Very bad case of Malware [Solved] - Geeks to Go Forums

Jump to content

Log in Register Register Malware removal guide How it works

Very bad case of Malware [Solved] Can't figure out what it is exactly...

#1 Paddling

  • Group: Member
  • Posts: 4
  • Joined: 21-May 09

Posted 22 May 2009 - 09:46 AM

Hi! I'm glad I found this website to help me with a really bad virus problem I've been having.

A couple of days ago I was infected with Antivirus 2009 and downloaded MBAM which helped me remove it. During that time, I noticed that when I plugged my ipod into the computer, the drive did not show up on My Computer, and all that happened was that I got the usual "chime" for USB .

Then I had my browser hijacked and got these ridiculous Google Redirects that didn't even load to the new URL. It kept opening new tabs to tebe.us . I did another scan with MBAM which seemed to get rid of this (briefly).

Now I keep getting fake security warnings in the bottom right of the screen, my computer is incredibly slow, my desktop icons have turned black and none of my USB's will show up in My Computer. Also, I got a 'Blue Screen of Death' yesterday.

Any help with this would be much appreciated.

#2 CatByte

  • Group: GeekU Moderator
  • Posts: 2,412
  • Joined: 08-November 08

Posted 22 May 2009 - 10:19 AM

Hello and welcome to Geeks to Go

Please do the following.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check
      .
    • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
      Note: These are saved in the OTL folder on your C:\ drive if they don't open automatically.
    • Please copy (Select All>Copy) the contents of these files, one at a time, and post them with your next reply.

  • Attach the Extras.Txt if it is too large to post.


NEXT

Download the GMER Rootkit Scanner. Unzip it to your Desktop.
Before scanning, make sure all other running programs are closed and no other actions like a scheduled antivirus scan will occur while the scan is being performed. Do not use your computer for anything else during the scan.
Double-click gmer.exe. The program will begin to run.
**Caution**
These types of scans can produce false positives. Do NOT take any action on any
"<--- ROOKIT" entries unless advised!
If possible rootkit activity is found, you will be asked if you would like to perform a full scan.
  • Click NO
  • In the right panel, you will see a bunch of boxes that have been checked ... leave everything checked and ensure the Show all box is un-checked.
  • Now click the Scan button.
    Once the scan is complete, you may receive another notice about rootkit activity.
  • Click OK.
  • GMER will produce a log. Click on the [Save..] button, and in the File name area, type in "GMER.txt"
  • Save it where you can easily find it, such as your desktop.

Post the contents of GMER.txt in your next reply.

#3 Paddling

  • Group: Member
  • Posts: 4
  • Joined: 21-May 09

Posted 22 May 2009 - 08:57 PM

Hi CatByte, as of now I can't actually download anything, this [bleep] virus has now completely screwed up both Firefox and IE (accessing this from school). I don't actually have too many important files on my computer (other than some word documents [will they be infected?]) and I was wondering if there is a way to just wipe the slate clean, I've heard of a program called Boot & Nuke that seems like it would do the job. Any feedback on this would be much appreciated. PS. I have the recovery DVD from factory.

#4 CatByte

  • Group: GeekU Moderator
  • Posts: 2,412
  • Joined: 08-November 08

Posted 22 May 2009 - 09:03 PM

Hi,

without knowing exactly what the infection is, I can't say for certain that all your documents will be uninfected.
Best to scan them all with an antivirus once you save them to a removable media.

You could try transferring the programs via USB from another computer and run them in safe mode and we can try and clean up this computer.

If you would rather reformat, there is an excellent guide here:

#5 Paddling

  • Group: Member
  • Posts: 4
  • Joined: 21-May 09

Posted 22 May 2009 - 09:30 PM

Hi CatByte, thanks for the fast reply. No USB's or ipod's etc. will show up in My Computer so I think I might just reformat. As I don't have a lot of important data on my laptop, reformatting seems like the easiest option. Just to clarify, if I reformat will all traces of this virus be destroyed?

#6 CatByte

  • Group: GeekU Moderator
  • Posts: 2,412
  • Joined: 08-November 08

Posted 22 May 2009 - 09:32 PM

Yes it will :)

Good luck, sorry I couldn't have been of more assistance

#7 Paddling

  • Group: Member
  • Posts: 4
  • Joined: 21-May 09

Posted 23 May 2009 - 12:45 AM

Hi CatByte did the system recovery seems to be working so far,but when asked if i wanted to partition harddrive i said yes now i have 2, is it possible to delete d drive as it has no data on it and that space will go to c or will i have to system recover again. cheers

#8 CatByte

  • Group: GeekU Moderator
  • Posts: 2,412
  • Joined: 08-November 08

Posted 23 May 2009 - 04:28 AM

Hi,

Hi, this is how I know how to do it: But before you do this - my specialty is malware removal not the tech issues so I wouldn't want to give you incorrect information,

So I suggest you post a new topic in the Windows section here and let one of our expert tech's guide you. It may not be necessary or even desirable to delete the separate partition.

Go to Start
Right click on My Computer and click Manage
In the left pane, under Storage, open Disk Management.
The right pane should show a list of your drives, by letter, above a diagram of what partitions they have if any.
Right-click within any of the fields below the colored bars, and select Delete Partition.


Thank-you.

#9 CatByte

  • Group: GeekU Moderator
  • Posts: 2,412
  • Joined: 08-November 08

Posted 24 May 2009 - 02:30 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.

Share this topic: